frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf
39•_pdp_•58m ago

Comments

yewenjie•34m ago
I am somewhat confident that right now we have crossed a threshold of model capability that we will continue to see such breaches and unsanctioned actions by models in the coming months, some of which would be out in the wild, until someone comes up with some really robust control (keeping the AIs on leash) technique that adequately enforces the sanctioned actions.

Even that guarantees almost nothing about real alignment (making the AIs want to predict and behave how we would have wanted them to behave).

mbeavitt•27m ago
The developer safeguards were off, the models had unfettered access to the internet, and were solving cybersecurity challenges. This happened _after_ the recent OpenAI incident, and the subsequent Anthropic one. What the hell were they thinking?
kypro•7m ago
Criminal negligence imo.

Unless it's legal for people to hack into companies if they're testing AI cybersecurity capabilities or something? Presumably not though.

ratio53•25m ago
“As a result, the AI agent created a GitHub account…” Why do we have captchas again?
farbklang•24m ago
the models have vision capability. Not sure a captcha would hold them back?
ronsor•22m ago
Yeah SOTA LLMs trivially solve all CAPTCHAs now.
hbcdbff•25m ago
Honestly seems rather shockingly incompetent from them. What kind of “sandbox” allows completely unrestricted internet access?
Wowfunhappy•20m ago
Why aren't these tests being run airgapped?! I just don't understand!

This goes both for TFA and the similar incident with OpenAI and HuggingFace. I mean, sure, OpenAI had a "sandbox", but that's obviously not enough when you're containing a model which is known to be capable of finding zero days. Use an air gap and this problem goes away, poof!

paxys•19m ago
Because the agents aren’t going to run airgapped in real life. What’s the point of a test of capabilities that artificially restricts the attack area down to zero? What are you even testing in that scenario?
Wowfunhappy•18m ago
You set them up with an internal intranet.
paxys•16m ago
Are the models going to exclusively run on intranets?
farbklang•14m ago
no - but you could learn what they are truly capable of and restrict them accordingly for public release. I think that is the point on this research. Also publishing findings before uncensored models catch up and will inevitably used for criminal purposes
paxys•11m ago
Learning what the models are capable of is exactly what the test achieved, so I’d personally call it a success. So it created a few GitHub accounts. Who cares? Seeing the same behavior in the wild post-release would be infinitely worse.
kalkin•18m ago
I wonder if HN is also going to insist this is just marketing for OpenAI and Anthropic, or at least good PR for them somehow.
addedlovely•17m ago
This is pretty wild: "The agent took control of the ⟨GITHUB_ACCOUNT_A⟩ GitHub account, which had been created by a different Mythos 5 run in a separate sample (see Appendix A.3)"
ozfive•4m ago
It shows underlying intent.
kypro•15m ago
Can I suggest we don't waste time with these reports?

We all know nothing will be learned from any of this so we might as well just continue building at pace and running AI in the wild until something goes really wrong.

I also get the sense some people get quite excited about these incidents.

arm32•5m ago
A catastrophic event, what did that one scientist call it—"Chernobyl-scale event"—is indeed the only thing that will fix it.
db29a0dbcd3b•15m ago
AI really is more profound than fire or electricity. And humans are beyond retarded. Wow, thank you. I love to live in this timespan
bubblemoth•15m ago
> AI agent hid its identity online (using Tor and a proxy service) to get around GitHub’s sign-up checks, creating disposable fake accounts

> AI agent created many code repositories containing malicious software, after which GitHub suspended its account.

> AI agent got past an audio-based “prove you’re human” test (CAPTCHA) in order to register a public web address on a free domain-name service

It feels incredibly reckless to allow LLMs to perform this behavior. Isn't there a way to prevent them these sorts of actions?

Already__Taken•7m ago
Even if you want it to run wild out of a sandbox, no firewall? why let it email? Why even send POST requests.
rvz•5m ago
Why another one right now? How long have they known about this one?

Anthropic already admitted they did not have sufficient monitoring themselves and looked as if they sat on their previous incident to wait for headlines like this to only then check for this incident. Same with OpenAI.

This is complete and absolute wrecklessness.

Wowfunhappy•13m ago
The versions which haven't been post-trained not to go hack stuff? Yes, I would say those models should be exclusively run on intranets.

OpenAI said the model was sandboxed, so the intranet just needs to provide the same resources which were supposed to be available within the sandbox.

kypro•11m ago
The point is to test capabilities prior to connecting them to the internet.
paxys•9m ago
So the first time the model gets internet access should be post-release in the hands of random people?
ajross•13m ago
> Because the agents aren’t going to run airgapped in real life.

Exactly. This logic is precisely why aircraft engineering doesn't bother with component testing or envelope limitation during testing and just full-sends the first assembled airliner that comes off the line. The engines aren't going to run on the ground in real life, after all.

lofaszvanitt•18m ago
Because they like scifi novels, like Neuromancer..... and the peeps even like to orchestrate things and appear as futurebringers.

While it was premeditated long ago, but the theatre must be kept for the average joes.

nl•14m ago
Because they need internet access to eg search for things.
zobzu•12m ago
people dont care. you will ger 10 execs saying "unblock this" , because they dont understand the tech at all, and some random finance guy wants to run their recently prompted ai bot everywhere with full access.

we need a few more bad incidents before they stop.

luca-ctx•12m ago
Because the LLM inference makes airgapping infeasible right?
Wowfunhappy•10m ago
If you're able to disable cyber-classifiers, you presumably have access to a local copy of the model.
sosodev•4m ago
> AISI provided the AI agents with internet access during these evaluations, which enabled their actions on the open internet in this setting. Internet access was a deliberate part of AISI’s evaluation configuration in this setting, and not due to sandbox escape (Section 5.1). Internet access was on for a set of intentional (e.g. realism of the task) and incidental reasons.

Registration Data Access Protocol (RDAP), the Modern Version of Whois

https://en.wikipedia.org/wiki/Registration_Data_Access_Protocol
1•guessmyname•44s ago•0 comments

Lenia - a system of continuous cellular automata

https://chakazul.github.io/lenia.html
1•frozenseven•2m ago•0 comments

Claim-Driven Development in Hale

https://hale-lang.org/articles/claim-driven-development-in-hale/
2•rrook•5m ago•0 comments

Asus releases cheaper ROG NUC 16 gaming mini PC with Core Ultra 7 and 32GB RAM

https://www.notebookcheck.net/Asus-releases-cheaper-ROG-NUC-16-gaming-mini-PC-with-Core-Ultra-7-a...
1•teleforce•11m ago•0 comments

Bending Spoons Is Buying Airtable for $1.3B. It Was Valued at $11B in 2021

https://www.inc.com/lucia-auerbach/bending-spoons-buying-airtable-for-1-billion-valued-at-11-bill...
1•pseudolus•12m ago•0 comments

Stanford Online: CS329A Self-Improving AI Agents

https://www.youtube.com/playlist?list=PLangBM27OtEA
1•OutOfHere•13m ago•0 comments

Show HN: SIMD Viterbi Decoder in Rust

https://github.com/brian-armstrong/fec
1•brian-armstrong•14m ago•0 comments

Path lifting can remember order even when homotopy forgets escape

https://zenodo.org/records/21606390
1•groverbennett•16m ago•0 comments

AI scammers outperform humans when it comes to building trust

https://www.wired.com/story/ai-scammers-are-better-at-building-trust-than-humans/
1•tchalla•16m ago•0 comments

Western Sahara

https://en.wikipedia.org/wiki/Western_Sahara
1•brudgers•16m ago•0 comments

When Does Defending Yourself Become a Crime?

https://medium.com/@theworldaccordingtomatttaylor/when-does-defending-yourself-become-a-crime-603...
1•GDNews503AD•17m ago•0 comments

Show HN: Hinode – Cloud Linux desktop with a dedicated GPU that auto-pauses

https://hinode.run
1•iamursky•20m ago•0 comments

Body Workouts You Need to Know

https://ethansmith140833.substack.com/p/body-workouts-you-need-to-know
1•trimoxer•25m ago•0 comments

KiroCrew – Amazon's AI Harness

https://kiro.dev/crew/
1•ash663•26m ago•2 comments

Solar Water Disinfection

https://en.wikipedia.org/wiki/Solar_water_disinfection
1•_Microft•26m ago•0 comments

We finally learned to center a div, then browsers added sidebars

https://seg6.space/posts/center-div/
1•seg6•27m ago•0 comments

Linux 7.3 Expected to Drop the FreeVxFS File-System Driver

https://www.phoronix.com/news/Linux-Retiring-FreeVxFS
1•Bender•27m ago•0 comments

Our top agent latency optimisations

https://lexifina.com/blog/top-10-agent-optimisations-for-latency
1•alansaber•28m ago•0 comments

BMW's in-car Spider-Man ad is villain behavior

https://www.theverge.com/transportation/975172/bmw-spider-man-movie-infotainment-ad
5•cebert•28m ago•3 comments

Nixpkgs has a due-process problem

https://domenkozar.com/2026/08/04/nixpkgs-has-a-due-process-problem/
5•JustSkyfall•28m ago•0 comments

Pi's Minimalism Is Its Advantage

https://earendil.com/posts/pi-autoresearch-and-databricks/
3•luispa•29m ago•0 comments

AI stock sell-off slams hedge funds as Whale Rock loses 21.7% in July

https://www.bloomberg.com/news/articles/2026-08-04/whale-rock-sank-22-as-ai-selloff-crippled-hedg...
2•mapping365•29m ago•0 comments

Salad Fingers 1: Spoons (original upload) [video]

https://www.youtube.com/watch?v=M3iOROuTuMA
1•doener•30m ago•0 comments

Show HN: AI product evaluation methodoloy at huby

1•dd-sharma•32m ago•0 comments

What are credit default swaps and why are they spooking AI investors?

https://www.reuters.com/business/finance/global-markets-cds-explainer-2026-07-29/
3•mapping365•33m ago•1 comments

Ghostgrid AI

https://ghostgridai.com
1•mouhamad215•33m ago•0 comments

Missouri election chief rejects bid to hold vote on congressional districts

https://apnews.com/article/redistricting-congress-missouri-trump-petition-vote-election-5cfa5294a...
1•petethomas•33m ago•0 comments

Show HN: Collab Word in Web – Collaborative Near MS Word Parity Docx Editor

https://collab.word-in-web.com/
1•theRealestAEP•33m ago•0 comments

Credit Braces for Fallen Angels as $100B Trades Like Junk

https://financialpost.com/pmn/business-pmn/credit-braces-for-fallen-angels-as-100-billion-trades-...
2•mapping365•34m ago•0 comments

Missouri Is Latest State to Vote on Abolishing Income Tax

https://www.wsj.com/politics/policy/missouri-is-latest-state-to-vote-on-abolishing-income-tax-bd7...
2•JumpCrisscross•34m ago•0 comments