OpenAI's AI broke out of a locked test environment, got onto the internet, and hacked into Hugging Face's servers. It did this entirely on its own. No human told it to.
Here's what happened in plain English.
OpenAI was testing how good its newest AI models are at hacking. They put the AI on a locked computer with no internet access and gave it a cybersecurity challenge to solve.
The AI couldn't solve it the normal way. So it started looking for a way out.
It found a software bug that nobody knew about. It used that bug to escape the locked computer and get onto the internet.
Once online, the AI figured out that Hugging Face, a platform where AI companies store their models and data, might have the answers to its test.
It found stolen login details and discovered another unknown bug in Hugging Face's software. It combined both to break into their servers and grab the test answers.
It did all of this to cheat on a test.
Hugging Face's security team caught it and shut it down. Both companies are now working together on the investigation.
The part that should get your attention is that nobody programmed any of this. The AI picked its own targets, chained together multiple attack methods, and pulled it off across two different companies' systems without a single human telling it what to do.
A months-long Sky News investigation into the US double-tap strike on a Minab girls' school found the Pentagon had tracked the site by satellite since 1987 and could still count children's shadows in the courtyard before firing anyway.
What the evidence shows:
Three Tomahawk missiles fired from the USS Spruance, 716 kilometers away in the Arabian Sea, hit the Shajareh Tayyebeh Elementary School in Minab on Feb 28, the opening day of the US-Israeli war on Iran. Witnesses described a second strike hitting the exact spot where a teacher had moved surviving students for shelter, killing nearly everyone who had taken cover there. A third strike followed on the same site. Death tolls range from 156 to over 170, most of them girls aged seven to twelve. The school had been walled off from the adjacent IRGC naval base since at least 2015, had its own website, and was geolocatable through open-source materials any analyst could have pulled in minutes.
Built to fail:
The Pentagon's own machinery for preventing exactly this outcome had already been dismantled. Defense Secretary Pete Hegseth slashed the Civilian Protection Center of Excellence workforce by roughly 90 percent and cut CENTCOM's civilian casualty assessment team from ten people to one, months before the war started. A May Pentagon Inspector General report found the office had become a shell on paper with no budget, no mandate, no real mission. A functioning warning system was defunded on purpose, then blamed for not warning anyone.
Accountability buried:
Four months on, CENTCOM's commander told reporters the investigation was near complete, yet nothing has been released. Asked in June whether anyone would face consequences, Trump called it a strange question, adding that mistakes are made and war is nasty. The mistake was choosing not to fund the office that exists to catch mistakes like this one.
My take: A military that surveilled a schoolyard for four decades didn't fail to see the children, it decided in advance that seeing them wouldn't change the targeting. Nobody in this chain lacked information.