One thing about this OpenAI / Hugging Face incident really bothers me. Hugging Face says the intrusion was driven “end to end” by an autonomous AI agent system.
But how do they actually know that?
Victim-side telemetry can show automation, speed, thousands of actions, short-lived sandboxes, changing infrastructure etc. It cannot show what happened upstream.
It cannot tell us whether humans changed prompts, restarted runs, selected successful paths, provided more context, redirected agents or manually helped at certain points. We also don’t know what was actually decided by a model and what was simply automated by the surrounding agent framework.
Maybe OpenAI has all those traces. Fine. Then publish them.
Show the prompts, tool calls, failed runs, model handoffs, restarts and human interventions. Without that, “end-to-end autonomous” is a claim, not a proven technical finding.
The forensic-refusal dataset Hugging Face published proves something much smaller: https://t.co/LemUxeaY4V
It shows that Claude refused to analyze one small Python backdoor while GLM 5.2 completed the analysis. That is a valid example of hosted-model guardrails getting in the way of incident response. But this is not evidence that the intrusion itself was carried out end to end by an autonomous agent.
And this claim matters because it pushes a very specific idea into people’s heads: AI agents can now independently find zero-days, escape sandboxes, move laterally, steal credentials and compromise companies.
Then comes the second part of the story: Hugging Face used local AI models to investigate the AI attacker “at machine speed”.
So the message basically becomes:
- AI attacked us
- AI helped save us
- Therefore, everyone needs more AI
Come on 🙄
Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius.
You don’t need an AI defender to fix those things.
Even fairly basic controls like rate limits and temporary blocks across source IPs, accounts, tokens and job volume could have throttled at least parts of this activity and created a very obvious signal for an analyst to review. Add proper egress restrictions, isolated workers and credentials that do not open the door to production clusters .. none of this requires an LLM
Using a local model to analyze 17,000 events may have helped during the investigation. Good - I’m not questioning that. But that happened after the compromise.
What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch.
Maybe the attack really was fully autonomous. Then show the evidence. Until then, I don’t think this claim should be repeated as if it had already been proven.
Sources
https://t.co/1yi9ck5xWD
https://t.co/TSlel0Cyfz
https://t.co/LemUxeaY4V
What happened when objective reality hits OpenAi...
after the team circle-jerk because the sandbox containment is bombproof concrete...
also containing sand.
Speechless... but only because its no surprise when C-suites won't even listen to their own people practically begging/pleading for remediations because 'if' was several predecessors ago, and 'when' is overdue (and wonder why they walk?)
KNOWN Warning(s) prior incident:
Origin - 3 months
Genea - 5 m
Telstra - 5/7 m (depending who)
Medibank - 9 m
QANTAS - 9 m
Optus - 17 m (yes, one seven)
As I've just commented in one of our group-chats of my former soldiers: "Anyone... male, female, alpha... if you choose to put on a uniform and you [execute your duties] align with [the] morals, ethics & beliefs of protecting/preserving Australian interests; then as a community we should expect equity, fairness & accountability irrespective of rank or role."
When McKenzie and Masters pursue the senior ADF hierarchy and ministers from the same period with the same vigour they pursued BRS, only then can they boast about chasing this story to the ground. Until then, the culture of impunity for war crimes at the top will remain, and it's a culture perpetuated by these two.
FFS, you can't make this up...
Am I glad for not being involved as a former candidate to grip-up the Bureau's ICT lethargic malarkey & reticence to adress let alone for compliance?
Or guilty for not; and - seeing the tea-leaves for what they were - believing I could have prevented both the original textbook-failure &or the catastrophe that has now followed?
@AlboMP Yet another of your tweets aged like milk. Left out. In the sun. On a summers day.
I can't be 100% sure - maybe only 98-99% - that most Aussies would secure Hormuz themselves for the prices below; over what they are today under your reprehensible <cough> "government" perpetual failure to secure National Energy & Resources.
@AlboMP Yet another of your tweets aged like milk. Left out. In the sun. On a summers day.
I can't be 100% sure - maybe only 98-99% - that most Aussies would secure Hormuz themselves for the prices below; over what they are today under your reprehensible <cough> "government" perpetual failure to secure National Energy & Resources.
23 years ago today, I was an Airborne Infantry Platoon Leader jumping into northern Iraq with 999 of America’s best. One of my greatest honors was making that jump and then leading 40 men in combat for the next twelve months. Experience teaches a simple lesson: be careful assuming what the U.S. military can or cannot do.
The biggest threat to our national security is Defence Minister @RichardMarlesMP. He’s happy to spend $368B on a highly risky all-eggs-in-one-basket #AUKUS submarine procurement while other programs for essential capabilities are cut, or never approved. #auspol
While Finland spends two decades teaching digital literacy, Australia fumbles with age-gate theatre. The Albanese government's social media ban is the policy equivalent of a screen door on a submarine: technically present, ultimately futile, and engineered mainly to be seen.
An investigation into why serious jurisdictions are building better solutions, and what we actually owe young Australians. (My latest.)
Ban It and They'll Thank Us Later: Labor's Teen Social Media Panic https://t.co/P2C3Ry0ru1 via @UrbanWronski
Without transparency, there can be no accountability.
Without accountability, it is impossible to ensure responsibility.
@AlboMP has not just broken @ScoMo30 levels of secrecy but surpassed; achieving draconian-levels of FOI rejections & associated disclosure(s)
Earlier this week I spoke with @TheAusInstitute about the ‘NO right to know’ Bill that @AlboMP’s Govt has introduced into the Federal Parliament. Have a listen to the very disturbing nature of the proposed #FOI Act changes. #auspol https://t.co/VDWiH5brrE
I'm all about confidentiality... which is secrecy WITH transparency, & therefore [at least the intention of] accountability.
Combined with @AlboMP watering down & obfuscating Federal #ICAC, this is immoral & borderline criminal (change that law too?)
I fought @ScoMo30 on National Cabinet secrecy during the COVID pandemic. I won that fight because his secrecy declaration was inconsistent with the law. @AlboMP is smarter than Morrison. He’s trying to expand Cabinet secrecy by changing the law. #auspol https://t.co/QlMEMhqv1w
Hello,
When we announced we're facing potential termination from our hosting provider we received dozens of messages and overwhelming support. Thank you.
We are happy to announce we're getting our own dedicated infrastructure soon thanks to our friends over at @TorGuard.
To make a long story short, thanks to them we're getting bigboi equipment and bigboi machines. Our bandwidth and resource capabilities will be exponentially better than before. Lots of exciting news coming.
tl;dr faster speeds, more malware source code, more malware samples, and more malware papers
tl;dr tl;dr we gettin big