Live data from Hacker News

Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

cdn.prod.website-files.com

11–20 of 65 posts

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#11
post #6

“As a result, the AI agent created a GitHub account…” Why do we have captchas again?

the models have vision capability. Not sure a captcha would hold them back?

Yeah SOTA LLMs trivially solve all CAPTCHAs now.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#12
Why aren't these tests being run airgapped?! I just don't understand!

This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days. Use an air gap and this problem goes away, poof!

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#13

Why aren't these tests being run airgapped?! I just don't understand! This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days . Use an air gap and this problem goes away, poof!

Because the agents aren’t going to run airgapped in real life. What’s the point of a test of capabilities that artificially restricts the attack area down to zero? What are you even testing in that scenario?

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#14
post #13

Why aren't these tests being run airgapped?! I just don't understand! This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days . Use an air gap and this problem goes away, poof!

Because the agents aren’t going to run airgapped in real life. What’s the point of a test of capabilities that artificially restricts the attack area down to zero? What are you even testing in that scenario?

You set them up with an internal intranet.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#16

Why aren't these tests being run airgapped?! I just don't understand! This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days . Use an air gap and this problem goes away, poof!

Because they like scifi novels, like Neuromancer..... and the peeps even like to orchestrate things and appear as futurebringers.

While it was premeditated long ago, but the theatre must be kept for the average joes.

Sorry, I meant this for the huggingface incident.

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#18
post #13

Earlier quoted context omitted.

Because the agents aren’t going to run airgapped in real life. What’s the point of a test of capabilities that artificially restricts the attack area down to zero? What are you even testing in that scenario?

You set them up with an internal intranet.

Are the models going to exclusively run on intranets?

Re: Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

#19
Can I suggest we don't waste time with these reports?

We all know nothing will be learned from any of this so we might as well just continue building at pace and running AI in the wild until something goes really wrong.

I also get the sense some people get quite excited about these incidents.

Post reply on HN