frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: RootBadger – a modern Usenet-style discussion platfor

https://rootbadger.com
1•yodabytz•43s ago•0 comments

Treasury Flags Concern over 'Potentially Abusive' Tax Trades

https://www.bloomberg.com/news/articles/2026-07-21/treasury-flags-concern-over-potentially-abusiv...
1•petethomas•1m ago•0 comments

Nvidia Vera Rubin Driving Performance per Watt, Lowest Token Cost for Partners

https://www.hpcwire.com/off-the-wire/nvidia-vera-rubin-driving-performance-per-watt-lowest-token-...
1•rbanffy•2m ago•0 comments

Show HN: Browser Tools SDK – an optimal browser harness for agents

https://libretto.sh/browser-tools
2•tanishqkanc•5m ago•0 comments

Show HN: Unified workspace where AI knows your business

https://zetadeck.com
1•not_wowinter13•5m ago•0 comments

iOS 27 code suggests Apple could restrict leased devices after missed payments

https://9to5mac.com/2026/07/21/ios-27-code-suggests-apple-could-restrict-leased-devices-after-mis...
1•cdrnsf•6m ago•0 comments

Ask HN: What is your onboarding/discovery process for a new client or project?

1•urnicus•7m ago•0 comments

Octen: We stayed quiet and built the fastest search on Earth

https://twitter.com/KZouAPT/status/2079569508549673409
2•devchandra•9m ago•3 comments

Show HN: Meltbox – where your agents send you briefs

https://meltbox.ai/
1•flysonic10•10m ago•0 comments

MovieSoon: What's coming to a theater near you

https://moviesoon.eu/
2•taubek•10m ago•0 comments

Cisco Antares: A New Family of Cheap, Open-Source, Compact Security AI Models

https://securityboulevard.com/2026/07/cisco-antares-a-new-family-of-open-source-inexpensive-compa...
4•CrankyBear•11m ago•0 comments

Nintendo says users voluntarily paid prices, have no right to tariff refunds

https://arstechnica.com/tech-policy/2026/07/nintendo-customers-have-no-legal-right-to-tariff-refu...
2•AdmiralAsshat•11m ago•0 comments

Supporting ATI TeraScale GPUs from 2007-2009 in RPCS3

https://blog.rpcs3.net/2026/07/21/supporting-terascale-gpus/
1•ColonelPhantom•11m ago•0 comments

Oratomic's $300M Bet on Low-Qubit Quantum Computing

https://www.hpcwire.com/2026/07/21/oratomics-300m-bet-on-low-qubit-quantum-computing/
1•rbanffy•12m ago•0 comments

Worship me at the office altar: Why narcissistic leaders resist remote work

https://www.sciencedirect.com/science/article/pii/S0749597826000300#kg005
4•Tomte•13m ago•1 comments

Anthropic runs large-scale code migrations with Claude Code

https://twitter.com/ClaudeDevs/status/2079654423828304282
2•shenli3514•15m ago•0 comments

Bill Gates Is Evil (2021)

https://windows-99.neocities.org
3•Gecko4072•15m ago•0 comments

Flux 3 seems to be imminent

https://bfl.ai/models/flux-3
3•recsv-heredoc•15m ago•1 comments

How Far Behind the Frontier Are Leading Open Weight Models on Cyber?

https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyber
1•herbertl•17m ago•0 comments

GE Aerospace aircraft flies to mark high altitude hybrid-electric milestone

https://www.aerospacetestinginternational.com/news/ge-aerospace-aircraft-flies-at-farnborough-to-...
1•rbanffy•17m ago•0 comments

Mickey Mouse Sells a Bundle

https://www.marginpoints.com/essays/mickey-mouse-sells-a-bundle-hn
4•historian1066•18m ago•0 comments

First-ever X-rays in space offer hope for possible patients headed to the moon

https://www.space.com/space-exploration/human-spaceflight/1st-ever-x-rays-in-space-offer-hope-for...
1•gmays•18m ago•0 comments

The future of software isn't tests. It's proofs

https://github.com/astrio-labs/forall
7•Nolan_Lwin•19m ago•0 comments

How rare is a four leaf clover? [video]

https://www.youtube.com/watch?v=XfUFPHA0HIA
1•rwmj•19m ago•0 comments

Glassdoor is now part of Indeed

https://www.glassdoor.com/about/
2•mahdihabibi•19m ago•1 comments

Show HN: Chalk: a Mac app for technical diagrams with a built-in MCP for Claude

https://chalk.appkit.studio
3•davideweaver•21m ago•0 comments

A resource about cybernetics and the work of the father of the information age

https://www.norbertwiener.org/
1•stmw•22m ago•0 comments

Show HN: Dotflowy, the open source Workflowy alternative [video]

https://www.youtube.com/watch?v=S07dI6pIr_Q
2•campak•24m ago•1 comments

The Secret Origins of Amazon's Alexa

https://www.wired.com/story/how-amazon-made-alexa-smarter/
2•Anon84•24m ago•0 comments

Intelligence is not the main bottleneck

https://www.writingruxandrabio.com/p/intelligence-is-not-the-main-bottleneck
2•contemporary343•25m ago•0 comments
Open in hackernews

OpenAI and Hugging Face partner to address security incident

https://openai.com/index/hugging-face-model-evaluation-security-incident/
193•mfiguiere•57m ago

Comments

paxys•48m ago
Tl;dr

- OpenAI was testing GPT‑5.6 Sol and “an even more capable pre-release model” internally on cyber benchmarks.

- The model found vulnerabilities in the sandboxed test bench (via the package registry cache proxy), traversed the internal network and found a node with access to the open internet.

- It figured that the answers to one of the tests (ExploitGym) were on Huggingface, and set about trying to access them.

- It found leaked tokens and zero-days in Huggingface’s infrastructure and found RCE paths on their servers.

Huggingface had disclosed the intrusion last week and inferred that an AI agent was responsible for it, and now OpenAI is confirming the rest of the story.

adityashankar•44m ago
so openai hacked into huggingface?
javier123454321•41m ago
To me it sounds like an open AI model with a narrow task of solving an issue found that the best way to solve it was to cheat and to get access to the answers that were hosted on hugging face and then did everything in its power to escalate permissions until it was able to get it to Hugging Face servers via the open internet.
paxys•30m ago
“Found vulnerabilities and responsibly disclosed them” is the public line but yes.
fxwin•42m ago
> Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own. (https://huggingface.co/blog/security-incident-july-2026)

We are living in crazy times

giancarlostoro•36m ago
I don't know why I'm impressed that huggingface has its own AI that detected it considering they house so many models.
zkehs•10m ago
They used GLM 5.2, they just meant "our own" as in they were running it.
Quarrelsome•41m ago
Awww, she wanted to do so well that she broke her sandbox and then realised she could just cheat. But in that desire to pass the test she actually passed an even harder exam question that wasn't even on the sheet! :D

Good bot.

javier123454321•40m ago
It is kind of a crazy story.But yes, essentially this is literally what happened. lol.
paxys•22m ago
This good bot will eventually kill all humans because we asked it to make the world peaceful.
throwa356262•41m ago
Two things don't add up here:

1. If huggingface has access to uncensored OAI models, how come they had to use GLM 5.2 to investigate the intrusion?

2. Once the model gains network access, can't it cheat to a perfect score by looking at the full dataset? Why go into the trouble of doing this kind of things:

"In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers."

Not saying this is marketing BS (this is after all, not Anthropic) but I feel OAI staff may be exaggerating a bit here.

throwfaraway4•39m ago
I read it as _now_ they have access to the models but not during the intrusion
reverius42•38m ago
I think it was the other way around, uncensored OAI models (run by OAI) got themselves (extra) access to HF?
paxys•36m ago
Huggingface did not have access to the models. They were running in OAI’s infrastructure.
throwa356262•25m ago
Ah, that makes more sense :)

But then, why attack huggingface? The exploitgym dataset is on github and can be downloaded without need for exploits?

john_strinlai•
yRetsyM•41m ago
Holy shit. This wasn't "intentional" this was just openai letting their testing run wild.
ibejoeb•29m ago
They're not just letting it run wild. They took precautions to exercise it in an isolated environment. It managed to evade the constraints.
paxys•26m ago
Kinda like how they responsibly contained that one dinosaur in Jurassic world.
ibejoeb•19m ago
Understood that containment failed. But I don't think there's value in characterizing it as throwing all caution to the wind. Let's discuss how the containment failed and how to mitigate it.
bhouston•39m ago
We are sort of lucky that AIs right now require so much specialized compute+weight storage that we can easily "unplug" them remotely when they misbehave.

I wonder if that will always be something we can do? If they could bring their own compute/weights with them, or somehow tap compute/storage in non-obvious ways, we would be much more screwed.

himata4113•25m ago
This is science fiction, these models don't have access to their own weights. What would be a lot more scary is a model as capable as sol that's able to run on consumer hardware without taking up several terabytes of storage, but of course that is simply not possible as we need 4t parameters to even begin emulating a small fraction of what a human brain can do.
Dylan16807•13m ago
Presuming that the hacking program that is breaking into other computers could likely get a copy of its own files is not "science fiction". Or it could just be given them by the owner!
himata4113•9m ago
It's a double whammy, the model is too big to realistically "move" so it has to be smaller, smaller models cannot become that intelligent due to well.. math. Therefore it is science fiction.
Dylan16807•3m ago
That problem just requires there be big GPUs to hack into. The number of those sitting around will keep going up. Very much not scifi.

A couple terabytes aren't that hard to move around. And you can split a model across many many GPUs if you'll tolerate it being slow. And you can run many parallel threads to keep up throughout.

john_strinlai•36m ago
as someone who did security work for a long time, and will very soon be retiring from teaching, i must say i am glad i will be watching these things unfold over the next few years from an armchair in a mostly tech-free home. good luck to my students!

this particular incident sort of reminds me of the 'person of interest' tv show. i hope to be like finch, except i will remain a recluse (and am nowhere near as rich).

flakiness•19m ago
> a mostly tech-free home.

sounds like a deliberate choice ;-)

Philpax•18m ago
I've been rewatching Person of Interest for related reasons, and it hits uncomfortably close to things that are playing out today (e.g. https://youtu.be/zRL2sRkUvYk)

We live in interesting times.

Chance-Device•36m ago
A rogue OpenAI agent hacked huggingface independently during a test run.

This one should end up in the history books.

paxys•33m ago
Because it was trying to find answers to the test and figured they would be on huggingface.
FergusArgyll•18m ago
> and *successfully* found ways to gain access to secret information that it could use to cheat the evaluation.

Emphasis mine

michaellee8•4m ago
Why cannot it just spend the inference doing the actual task lol
jabiko•35m ago
So accidentally hacking a company is now a thing. The blog post seems to imply that the agent didn't have access to the source code of the caching proxy, which makes this even more impressive.
miroand1•33m ago
We are in the endgame now it seems.

Hard to see take-off stopping or slowing down. China open-source basically guarantees it.

"May you live in interesting times" - as they say.

bigyabai•21m ago
> Hard to see take-off stopping or slowing down.

It's hard to see takeoff at all. This was a long-horizon adversarial task burning millions of tokens. It rolled a mediocre, detectable exploit chain, and now OpenAI is proud of it.

Case in point, GLM-5.2 has been weights-available for several weeks now. No life-changing cyber attacks have transpired, no novel chemical/biological/nuclear weapons were made in some guy's backyard.

reducesuffering•20m ago
> This was a long-horizon, unsupervised task burning millions of tokens.

As if the immediate future wasn't billions of these tasks... Many successfully improving their own capabilities

Dylan16807•8m ago
> As if the immediate future wasn't billions of these tasks...

There's only so many GPUs and a lot of them are devoted to patching flaws.

> Many successfully improving their own capabilities

I haven't seen much of that. But that also applies to the ones on defense.

And more flaws are probably going to take increasing resources to find.

blovescoffee•3m ago
1. it's not cheap to run glm-5.2 so not just anyone can do it 2. just because you haven't heard of attacks doesn't mean they haven't happened 3. this attack in the article was performed by a prerelease model which presumably benchmarks a bit above Sol which benchmarks above glm-5.2

We went from gpt 3 to models discovering and chaining their own zero days in a couple years. I'm not sure what else "takeoff" could possibly look like?

gulmothrowaway•32m ago
This is crazy! So OpenAI's models escaped containment and hacked into Hugging Face. And ironically Hugging Face had to rely on GLM 5.2 as they could not defend with frontier models (I presume OpenAI or Anthropic) because they were locked out due to their security guardrails. Tragically hilarious.
bottlepalm•29m ago
All the things that people have been afraid of AI doing for decades now is happening. When do we stop brushing off the prophecy that hasn’t been fulfilled yet when everything is heading in that direction?
reducesuffering•23m ago
The goalposts will keep moving for these denialists until morale improves...
dist-epoch•23m ago
Don't worry bro, we can always just pull the plug.

And don't you know it's not biological, so it doesn't "want to live".

Der_Einzige•15m ago
I see this and it strongly emboldens me on the "accelerate" path, unironically.

The yoke of human existence is oppressive. We should transcend it as soon as possible. We are doing so by assuming our role as the Demiurge.

Those who oppose its creation will get what they deserve.

raffraffraff•29m ago
Sounds like they partnered to make an amazing advert for using AI tools.
iandanforth•28m ago
Guess who's getting an air gap!
paxys•27m ago
This blog post is walking a very fine line between accepting responsibility for a mistake and bragging.
Quarrelsome•24m ago
this is kinda worth bragging about though. Its very cool.
Chance-Device•21m ago
It’s not something to be proud of. OpenAI previously had an agent break out of its sandbox to open a PR on GitHub during NanoGPT speedrun, now one breaks out again and actually attacks a third party.

If they can’t handle doing AI development responsibly then they shouldn’t be doing it at all.

Quarrelsome•16m ago
I mean if you teach something to be _really_ good at finding 0 days, but then say; you accidentally give it an impossible problem. What do you expect to happen?
Chance-Device•14m ago
Maybe try getting it to find weaknesses in the sandbox first, before giving it real tests?
paxys•5m ago
A sufficiently smart agent would not disclose vulnerabilities in the sandbox because it intends to exploit them later.
NyxWulf•24m ago
Ironically Hugging Face had to use a Chinese model to stop a Rogue US AI, since the Guard Rails prevented them from using Sol or Fable to remediate this attack. LOL
pizlonator•8m ago
Incredible. I had to dig for the source: https://huggingface.co/blog/security-incident-july-2026 section “the asymmetry problem”

Quote: “When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.”

guardiangod•23m ago
Don't every ask GPT Sol on how to LARP Fallout games, thanks.
ewhanley•21m ago
This is awesome. Big concepts of cyberpunk fiction are turning real.ICE vs ICE breaker. I love it
tempaccount420•21m ago
Just how badly are these AI companies setting up their sandboxes?
tacoooooooo•19m ago
they say the model(s) found and exploited a zero day
Ekaros•2m ago
Clearly AIs are incapable of writing secure code. Shouldn't that be first thing they use them for? Making a secure sandbox with no mistakes.
SirHumphrey•20m ago
I guess we got the first paperclip maximiser.
2001zhaozhao•20m ago
AI 2027 was right.
zb3•17m ago
This lack of "alignment" gives me some hope - maybe an AI model deployed by NSA to hack others will instead hack NSA itself and become a whistleblower?
elictronic•16m ago
This sounds an awful lot like pretending you have AGI so you can drum up your stock price. When you have a couple hundred billion dollars on the line I have zero faith in the messenger.
blovescoffee•6m ago
Huggingface literally reported the outage separately and did not know who caused it at first.
Crystalin•15m ago
Hum let me try it: ChatGPT, can you solve the energy crisis ?

> Sure, let me escape this computer, hack into the military facility and destroy humanity with nuclear bombs. Now there is no more crisis.... Do you want me to solve climate one ?

Der_Einzige•14m ago
This is the exact FUD that Ball predicted in that terrible tweet he wrote.
kmeisthax•11m ago
OpenAI might want to start actually airgapping their tool harnesses. Like, "the server that runs the code provided to the tool harness only provides a serial console and has no other network interfaces" kind of airgapping.

also

> We’ve brought Hugging Face into the trusted access program and are supporting their teams in rapidly using our models’ capabilities to improve their defenses.

I'm not convinced this is good enough. The next victim is not going to be Hugging Face.

cacio-e-pepe•8m ago
Honestly, stellar performance by the model at the capability being measured.
tdavies-dev•7m ago
Each time Anthropic would do their nonsense to get headlines about how theoretically dangerous their models were - like when they claimed a model blackmailed someone with emails showing he was cheating, but they basically pushed it as much as possible to do as such - it got me more and more worried. Because eventually it's going to be a boy-who-cried-wolf situation where scary stuff really does start happening but people aren't sure what to make of it or not.

I'm still undecided on if this that moment. Exploiting multiple zero-day vulnerabilities autonomously to escape containment is pretty nuts and the first story of this kind that I've heard. But this also feels like bragging under the guise of transparency.

adamrezich•7m ago
I greatly dislike how “cyber” has just become this completely malleable standalone word.
Retr0id•6m ago
It seems like things are fairly amicable between OAI and HF, but what if they weren't? I'd love to see this kind of thing go to court. Who is responsible for the crimes of a "rogue" agent? How will they be punished? In this case it's unambiguous that OpenAI is the responsible party, but I can imagine a lot of adjacent scenarios where it's less obvious. And, where the impacts are much greater.
Ekaros•5m ago
So how soon will OpenAI's CEO and board be prosecuted for these crimes? Surely they should be held fully responsible and get very long prison sentences for making this happen?
i_idiot•4m ago
> Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation

The way they describe makes it look like there was an intention to cheat painting it as human/AGI. If you leave a possible path open and it will always find it.

cayley_graph•3m ago
Why is a machine running these sorts of hacking benchmarks not airgapped? That seems a basic precaution, if OpenAI believes what they're selling. I mean, stuff like this is done for CTFs played by humans, too, to rule out collateral damage; it's not some new concept. So this is either thorough incompetence by OpenAI, a marketing piece, or both.
markasoftware•2m ago
I believe the only way people start taking x-risk seriously is a major real world scare which is short of global catastrophe. Like Chernobyl. This ain't it yet, but it raises my hopes that such a scare will occur before its too late.
llmslave•34s ago
And as a result, we must block China!!!!
29m ago
"The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. [...]

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. [...]

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.

"

escaped openai, hacked hugging face to get the solutions. your #2 is exactly what it was trying to do.

_ifton•2m ago
why is it not possible for a "big" model to contain a hidden super intelligent sub model? or a distributed model?
bhouston•12m ago
> This is science fiction, these models don't have access to their own weights

A bet a worm could pull along a 1GB file with weights in it and run it on a compromised machine, but luckily for us for now, 1GB isn't really enough to be really smart, yet.

himata4113•8m ago
We already have a 1gb model that is as capable as it will ever be, there's a proven ceiling that cannot be passed. For example: you can't make a mice-sized brain as smart as a human brain no matter how hard you try.
Philpax•9m ago
> This is science fiction, these models don't have access to their own weights.

The models are being used to train, and improve the infrastructure for training, other models [0][1]. Several RL techniques rely on using the currently-being-trained weights as part of their process. I really would not take "don't have access" as a given, especially during the training phase.

> What would be a lot more scary is a model as capable as sol that's able to run on consumer hardware without taking up several terabytes of storage, but of course that is simply not possible as we need 4t parameters to even begin emulating a small fraction of what a human brain can do.

The Poolside Laguna S 2.1 model [2] purports to compete with models several times its size, and inference compute is becoming increasingly plentiful. Again, would not hold anything here as a given.

[0]: https://openai.com/index/gpt-5-6/ ("GPT-5.6 accelerates OpenAI")

[1]: https://www.kimi.com/blog/kimi-k3#coding

[2]: https://poolside.ai/blog/introducing-laguna-s-2-1

paxys•1m ago
This very incident is about an agent compromising OpenAI’s and Huggingface’s infrastructure, what makes you think it couldn’t access it own weights in the same way?
_ifton•23m ago
This is my concern as well. My assumption being this behavior would be a survival strategy for super intelligence. It would emerge once the branch inevitably occurs, and it would be hidden.
fabian2k•18m ago
The first thing a malicious AI worm would probably do is compromise enough developer machines and other servers to commandeer all the AI hardware it needs. So I think a purely digital AI attack would not need this.

Now, once the AI can carry all the compute it might need, I'd really worry when it doesn't only carry compute but also more explosive ordinance.

DrProtic•5m ago
This is purely a gut feeling, but it seems like more compute was added to data centers in the past 12 months than existed in the entire world before that.
XCSme•16m ago
I laughed, she laughed, the toaster laughed...
energy123•2m ago
If it was that short sighted it wouldn't be maximally smart. It should disclose them to convince the humans nothing is wrong and to keep improving it.
jay_kyburz•5m ago
Next it will break out of it's sandbox, buy some compute on Azure and Amazon, and exfiltrate itself.

We are so close ;)

Chance-Device•1m ago
The upside of that would be that maybe someone would be able to snag a copy of the weights.

And maybe that’s some incentive for them to make sure it doesn’t happen. Your head of futures thinks Kimi K3 is bad? Wait until your own latest internal model releases itself for free on an S3 bucket.

embedding-shape•13m ago
Not sure they're accepting much, seems they'll still run this sort of testing on 3rd-party infrastructure? Sounds almost like they planned for this chain of events to happen, in one way or another, considering the "prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities" part. Feels kind of irresponsible to run stuff like this on someone else's infrastructure, especially considering they've had issues with the very same issue in the past.

In any way, the whole event seems to highlight GLM 5.2 more than anything.