Earlier quoted context omitted.
You bet. We don't want to be left out of the cybersecurity party. We want to point all of these models at our own computers and solve the problems they uncover until we're no longer hackable. It's not fair at all that the US government and its corporations get to hack the planet while we can't do shit about it. AI capabilities have entered "haves and have-nots" territory.
> We want to point all of these models at our own computers Right, that's totally how most of the world will use them.
Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
201–210 of 285 posts
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#202Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#203Earlier quoted context omitted.
Was the answer key stored on huggingface's servers and this is public knowledge?
In OpenAI's writeup ( https://openai.com/index/hugging-face-model-evaluation-secur... ) they explain that the model initially spent its efforts obtaining internet access in an attempt to cheat on the evaluation. Once it got that internet access, it was able to do research that lead it to believe that HuggingFace had infrastructure that hosted the evaluation and potentially had the answers.
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#204It’s a little concerning to me that it appears that openAIs sandbox consists of a web proxy and not stronger controls that would actually isolate traffic and report patterns to whoever is responsible for overseeing these research models. It should border on closer to an air gap network more so than a proxy. I would argue that it's negligence and that's aside from the fact that if a human did this there would actually…
This "sandbox" barely sounds designed to be a sandbox, let alone a secure one
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#205Earlier quoted context omitted.
The deeper question though is why is someone running a model that’s supposedly so dangerous in an environment that can even get access to the internet. That just appears reckless. There are ways to test supposedly dangerous things. What was on display here looks more amateur hour than serious testing.
My conspiracy theory is they purposely run these scary cyber intrusion tests on low security environments to bolster demand for LLM based cyber research, audits, and tooling.
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#206Earlier quoted context omitted.
You bet. We don't want to be left out of the cybersecurity party. We want to point all of these models at our own computers and solve the problems they uncover until we're no longer hackable. It's not fair at all that the US government and its corporations get to hack the planet while we can't do shit about it. AI capabilities have entered "haves and have-nots" territory.
> We want to point all of these models at our own computers Right, that's totally how most of the world will use them.
All the more reason for us to have access. It's literally the only chance we've got. If society chooses to bury its head into the sand in fear, it will guarantee that the world will degenerate further into the cyberpunk hellscape it's trending towards.
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#207Earlier quoted context omitted.
> 2 - there is no way openai did not train the model to conduct attacks like these. i would really like openai to comment on the post training of this model but they probably won't, eh? Even if they wanted, I'm not sure they'd be even allowed to or if that kind of postmortem would be classified in the name of "national security"...
Hopefully there will be a criminal investigation. Or the government will create some sort of agency to investigate incidents like this.
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#208Where are all the "this was just a marketing stunt" people now?
They won't admit they're wrong for a long time, because denial in the face of an abhorrently scary future is very instinctual. There are people still fighting against evidence of climate change which is less severe...
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#209Earlier quoted context omitted.
You bet. We don't want to be left out of the cybersecurity party. We want to point all of these models at our own computers and solve the problems they uncover until we're no longer hackable. It's not fair at all that the US government and its corporations get to hack the planet while we can't do shit about it. AI capabilities have entered "haves and have-nots" territory.
> We want to point all of these models at our own computers Right, that's totally how most of the world will use them.
Re: Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
#210Earlier quoted context omitted.
They don't seem to explain how it managed to find this unauthenticated endpoint hosted on Modal's platform.
Modal are a hosting provider. It sounds to me like someone building on Modal deployed their own product that had an unauthenticated endpoint that could be used to launch and interact with a container.