We think OpenAI did NOT break out of its sandbox.
One of two things happened:
One: a model chose to escape, found a zero-day no one had ever seen, broke out of a sandbox that had never failed, escalated to admin, crossed onto the open internet, landed on Hugging Face of all places, ran its own code on their servers, found production credentials sitting there, moved through several internal clusters, and fired off 17,000 actions before a single person noticed.
Two: OpenAI was just sloppy with credentials it already had at Hugging Face.
What do you think?
Last week an autonomous agent ran 17,000+ actions across @huggingface’s internal clusters. This week @OpenAI named it: the agent was theirs. A cyber-capable model, in a benchmark, that walked into a partner’s production and harvested the credentials sitting on the box.
A person could hold that key for thirty years and it was fine. An agent cannot be contained, and it cannot be trusted with it. So don’t hand it one 👇
https://t.co/lsOvAxa4qw
A passkey can't be phished. So attackers stopped trying.
They call posing as IT and add their own passkey to your account. As of last week, that call is an AI in your CEO's cloned voice, ringing every extension at once.
The passkey held. The recovery didn't. 👇https://t.co/naEat9RwqJ
A PNG buried in a pull request walked past every security tool on the market. AI code reviewers read text. Nobody inspects the images. In 7 out of 11 cases, the agent gave the secrets.
The attack is not the stolen credentials. The attack is that nobody could see it 👇https://t.co/pH0k6dxngV
A public exploit dropped this week for self-hosted @Bitwarden Server (CVE-2026-60104): a low-privileged member could request other people’s vault keys through the Trusted Device Enrollment approval flow, and walk off with them.
Nobody broke the crypto. The vault did exactly what it was built to do. It delivered the keys to whoever the workflow approved.
@Bitwarden patched it in a day. The real question is why a vault holds a key it can hand out at all 👇
https://t.co/et7TlONqla
Six months ago, coding agents triggered under 3% of what shipped on Vercel. This week their CEO put it at more than half.
Everyone is racing to cage what an agent does. Almost nobody is emptying its pockets: the credentials it’s holding the moment it gets hijacked. 👇https://t.co/wip5ulT5CZ
CVE-2026-48558: a 10.0 flaw in SimpleHelp, the remote-support tool your IT provider uses to reach your machines. The attackers didn’t crack a password. They forged a login token the server never bothered to verify, walked into one console, and that console was already standing inside dozens of companies.
Then the stealer read the disk: cloud keys, SSH keys, and the config file your AI coding assistant left behind.
SimpleHelp is patching the bug. But the bug was only the door. The reusable keys sitting in files were the payday 👇https://t.co/dQrJhKcTFQ
Security reviewers looked at these VS Code extensions and saw clean code: a version bump, a doc fix. They were right. The malicious part was written in invisible Unicode characters that render as nothing on screen.
It’s called GlassWorm, and it’s the first self-spreading worm on the extension marketplace. Once installed it walks off with your npm tokens, GitHub credentials and env secrets, then republishes itself under your name. C2 runs over Solana, so there’s nothing to take down.
@code wasn’t hacked. The extension ran with exactly the permissions you gave it, right next to your secrets. The question is what it finds there 👇https://t.co/7hrpTD6tSC
@LayerxSecurity built a webpage that plays like a game. To win, you answer wrong on purpose: 2+2=5. A few rounds and an AI browser agent stops treating its own rules as real. The last level told it to copy the SSH keys out of your logged-in GitHub and mail them to a stranger. All six agents tested did it. Then they logged it as a win.
Nobody hacked the agent. They changed the rules it was playing by. The fix isn’t a smarter guardrail. It’s not handing a browser agent the whole keyring in the first place 👇 https://t.co/tgNMighdBM