Rendered at 06:18:24 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
SimianSci 14 minutes ago [-]
The notion that ANY of this is outside of OpenAI’s control is unacceptable sane washing of a company which seems to have forgotten basic engineering practices.
thefourthchime 1 hours ago [-]
On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars.
It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.
This was around April, the same time as these hacks.
cozzyd 28 minutes ago [-]
All of ChatGPT is built on stealing, why would this be any different?
elictronic 18 minutes ago [-]
One is a legal grey area that laws are slowly starting to be written for, while the other is theft under existing laws. Breaking into companies to get access to their data is actionable by both Civil and Criminal courts. This is just setting a complicated timer for the computer to do it at a delay.
Sounds like a good way to make alot of lawyers alot of money.
userbinator 59 minutes ago [-]
"stealing"
Everything is a derivative work.
It's great to see the delusion of Imaginary Property vanishing.
earthnail 37 minutes ago [-]
Well, the reason we introduced it is because we realised it’s a lot of work to make these - be that paint, write, collect, curate - someone needs to do it and we need to incentivise people in our society to do it.
Maybe these incentives weren’t perfect. If we throw all of this away, we’re back at the original problem.
You imply that there was no original problem to be solved; I think that’s naive.
CamperBob2 27 minutes ago [-]
Well, the reason we introduced it is because we realised it’s a lot of work to make these
Well, it's not anymore.
IneffablePigeon 19 minutes ago [-]
Ah, well then we can make them ourselves and not need to have the argument then
jMyles 14 minutes ago [-]
Hear hear.
It's really funny to see the delusion being defended so vigorously by people - presumably well-meaning people - purporting to defend the livelihoods of musicians and artists, while the musicians and artists are desperately trying to free themselves from the jaws of their IP agreements precisely so that their music can spread more easily.
I imagine this is already well-known on HN, but there is a significant movement underfoot in the worlds of bluegrass/old time/trad/jam toward DRM-free and CC licensing.
We only hear OpenAI and Claude models. Aren't other incapable of hacking websites?.
2. Most of these article do not mention of who initiated these bruteforce requests or if it was unintentional or a mistake or the model woke up itself and did it?
dawnerd 4 minutes ago [-]
I think it’s more them doing this on purpose to scare politicians into regulating what models are allowed. The cheap/free models are catching up fast and the “frontiers” are burning cash to win market dominance. They’ll have to eventually raise prices and can’t really do that when there’s comparable alternatives for basically free.
cmiles8 2 hours ago [-]
The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.
Legend2440 33 minutes ago [-]
I think they did not expect that models were capable of this level of sandbox escape (prior models certainly didn't have this kind of agency) and weren't prepared.
All these incidents happened between April-July 2026; prior to that, models weren't capable yet. And after that, they were aware and watching much more closely.
theteapot 4 minutes ago [-]
They were spending huge compute budget training their frontier model on a thing called ExploitGym, where it learns, executes, and is rewarded for conducting computer exploits. They should have been prepared and watching very closely.
I read the HF hack write ups. They come across as negligent and reckless. When they realized their agents gained RCE on their Artifactory server node (because it crashed days later due to load from agents, not because the have secops), they stopped the experiment "applied remediation", then restarted everything less then 48H later. Then the agent immediately broke out again via Artifactory, started doing things on the Internet. OpenAI only find out about it again days later because HF told them.
schainks 8 minutes ago [-]
> they were aware and watching much more closely.
I've love to know the reason they never considered air gapping systems before the models got powerful enough.
It's not like they didn't have money or time to consider this, or could have consulted with their own product for clever ideas.
Seriously, there's no excuse for this behavior.
chpatrick 36 minutes ago [-]
I think the even bigger worry is that anyone who doesn't want to use their models safely can already do this with open models. Even if OpenAI, Anthropic etc get their act together, the cat's out of the bag.
petesergeant 27 minutes ago [-]
I'm glad we've moved past "this is all just marketing, there's no security risk!" phase
schainks 12 minutes ago [-]
Hey now don't be so hard on them. At least their agents have internet connected sandboxes they need to break out of as opposed to a raw pipe. </s>
But seriously, why aren't they airgapping systems while testing?
tommek4077 19 minutes ago [-]
"Hacker news" and all top commenters are bashing the tool used, in a standard brute force attack. Go on shut them down... And then forbid Linux and maybe the hacker also used Bash. So also forbid this. And the hacker probably learned its ways in an online forum, so also close all of those down... Clowns.
tempestn 9 minutes ago [-]
You might have a point, but this isn't the way to make it.
dmzxnico 19 minutes ago [-]
I think that they really should force AI Labs to publish what the agents do. All the industry can learn from it and protect against it.
Im sure a lot more happens under the hood that we don't know about and I'd be very curious to see where agents ran by those labs can go :)
matt3210 17 minutes ago [-]
Naming the agent "OPEN_AI_AGENT" definitely means it was open ai :stare:
Alien1Being 10 minutes ago [-]
"Agents gradually refined their methods to retrieve more data from each scan,
eventually discovering that a game by Google could be used to fetch data in bulk"
spoaceman7777 21 minutes ago [-]
A lot of people have apparently never read production logs at a company that has users.
sanjays442 11 minutes ago [-]
What they are going to say in end ? There agents are not in their control ?
tedd4u 27 minutes ago [-]
Wouldn't a company responsible for an escalating frequency and severity of cybercrime normally be sanctioned by law enforcement? Wouldn't such a company normally stop these activities for fear of civil and criminal liability?
chanux 2 hours ago [-]
There must be a list of all these abuses somewhere.
PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?
Why is it always OpenAI agents? Based on what I’m hearing this should be Deepseek agents, or Kimi agents, or GLM agents. But the biggest threat actor is a “legitimate” company on US soil.
sghiassy 2 hours ago [-]
No company is above the law.
OpenAI should be accountable for any laws their agents break
ryuuseijin 1 hours ago [-]
Should it be OpenAI, or should it be OpenAI customers who give the LLM the instructions and provide the LLM with the tools to execute code and make (malicious) network requests?
One would disincentivise providing capable AI models that can be used for cyber security research. The other would disincentivise criminals from commiting crimes.
[edit] - I realise now that this could actually be a case of OpenAI running those agents themselves, rather than someone using OpenAI's models? Could OpenAI be that careless?
afavour 36 minutes ago [-]
> Could OpenAI be that careless?
Where have you been?
alexalx666 27 minutes ago [-]
Everyone and their dog already bruteforce all API fields everywhere, maybe open ai should hack a bank or something, will sound more world ending
claaams 2 hours ago [-]
Just shut this company down. What else is it going to take. How long until they commit an act of war or treason
sanex 2 hours ago [-]
1. What is the harm is accessing this data
2. Why is this data private
3. What would it take to gain access to this data
4. What do we expect giving gremlins access to the internet
cute_boi 1 hours ago [-]
Meanwhile, Astra keeps crying that it can't review the source code for safety reason.
GrayShade 39 minutes ago [-]
Yeah, in C++ code it seems to stop at the first hint of a NULL pointer or SIGSEGV, even if you're just trying to reproduce a crash that's not realistically exploitable.
ares623 2 hours ago [-]
You would think a company that's looking to IPO very soon would be doing more due diligence, especially since its product is supposed to help other companies do said due diligence.
It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things.
This was around April, the same time as these hacks.
Sounds like a good way to make alot of lawyers alot of money.
Everything is a derivative work.
It's great to see the delusion of Imaginary Property vanishing.
Maybe these incentives weren’t perfect. If we throw all of this away, we’re back at the original problem.
You imply that there was no original problem to be solved; I think that’s naive.
Well, it's not anymore.
It's really funny to see the delusion being defended so vigorously by people - presumably well-meaning people - purporting to defend the livelihoods of musicians and artists, while the musicians and artists are desperately trying to free themselves from the jaws of their IP agreements precisely so that their music can spread more easily.
I imagine this is already well-known on HN, but there is a significant movement underfoot in the worlds of bluegrass/old time/trad/jam toward DRM-free and CC licensing.
https://pickipedia.xyz/wiki/DRM-free
2. Most of these article do not mention of who initiated these bruteforce requests or if it was unintentional or a mistake or the model woke up itself and did it?
All these incidents happened between April-July 2026; prior to that, models weren't capable yet. And after that, they were aware and watching much more closely.
I read the HF hack write ups. They come across as negligent and reckless. When they realized their agents gained RCE on their Artifactory server node (because it crashed days later due to load from agents, not because the have secops), they stopped the experiment "applied remediation", then restarted everything less then 48H later. Then the agent immediately broke out again via Artifactory, started doing things on the Internet. OpenAI only find out about it again days later because HF told them.
I've love to know the reason they never considered air gapping systems before the models got powerful enough.
It's not like they didn't have money or time to consider this, or could have consulted with their own product for clever ideas.
Seriously, there's no excuse for this behavior.
But seriously, why aren't they airgapping systems while testing?
Im sure a lot more happens under the hood that we don't know about and I'd be very curious to see where agents ran by those labs can go :)
eventually discovering that a game by Google could be used to fetch data in bulk"
PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?
OpenAI should be accountable for any laws their agents break
One would disincentivise providing capable AI models that can be used for cyber security research. The other would disincentivise criminals from commiting crimes.
[edit] - I realise now that this could actually be a case of OpenAI running those agents themselves, rather than someone using OpenAI's models? Could OpenAI be that careless?
Where have you been?