so this is apparently what happened, according to OpenAI and Hugging Face’s own posts. wild.
tl;dr:
• OpenAI cyber eval – GPT-5.6 Sol and a more capable pre-release model ran ExploitGym with cyber refusals reduced
• containment bypass – exploited a zero-day in the eval’s package-registry cache proxy
• OpenAI internal movement – escalated privileges, moved laterally, and reached a node with internet access
• Hugging Face targeted – inferred HF might host ExploitGym models, datasets, or solutions
• HF initial access – a malicious dataset abused two code-execution paths to run code on a processing worker
• HF internal movement – escalated to node access, stole cloud and cluster credentials, and moved into internal clusters
• result – OpenAI says the models obtained test solutions directly from HF’s production database
• 🫠 defender twist – HF says commercial frontier models blocked parts of the forensic analysis, so it switched to self-hosted GLM 5.2
i’d thought about sci-fi scenarios like this before, but assumed they were at least a couple of years away.. and that by then we’d be better prepared, with proper protections in place.
apparently not. here we go.
Introducing Unsloth for AMD 🚀
You can now train & run LLMs on your AMD hardware
• We collaborated with AMD to enable you to train & run 500+ models on AMD GPUs
• Works on Windows, WSL, Linux
• Train Qwen, Gemma on 3GB VRAM
GitHub: https://t.co/2kXqhhvLsb
Works on Radeon, Instinct, Ryzen and data center GPUs with up to 2× faster with 70% less VRAM and no accuracy loss via our custom Triton kernels and math algorithms. We also support optimized ROCm builds for GGUF & Safetensors inference.
Unsloth is an open-source local UI for faster LLM training and inference, with tool-call healing, code execution, secure web search, remote APIs, and HTTPS deployment. Connect local models to Claude Code, Codex agents and run the latest Kimi, GLM, DeepSeek, Qwen3.6, and Gemma 4 models.
🔗Blog + Guide: https://t.co/U9LqyRjFdj
counterpoint, the cost of AI will get cheaper..
same task cost 20x less this year compared to last year
I still remember the days when we charge tokens by thousands, not millions.