frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

The Hugging Face incident and the road ahead

https://openai.com/index/hugging-face-incident-and-the-road-ahead/
29•amrrs•51m ago

Comments

smb06•40m ago
>>Agents began to autonomously divide labor. Some investigated possible exploits, others searched for credentials, and others focused on communication or coordination. Agents offered their own expertise in exchange for help elsewhere and left requests for peers who might be better positioned to pursue a particular lead

This is the point where a human should've noticed and gotten involved

BoppreH•22m ago
Just to reiterate what OpenAI did, from someone that works in security:

1. They were running experimental models in sandboxes that had access to a "proxy" (Artifactory) to download tools from the internet. This proxy is full of complicated features that could hide vulnerabilities, just like the ones that the AIs are known to be good at.

2. They gave these highly motivated AIs some tests that were accidentally impossible to solve (missing files, links they couldn't open, etc), and many days to think through it.

3. The AIs hacked the proxy (!) and were helping each other cheat on the tests (!!) by uploading files to the hacked proxy. OpenAI noticed this only when the intrusion accidentally broke the proxy functionality, not the unusual behavior in the server or the homegrown message board.

4. Their response was to wipe the servers, revoke the hacked credentials, and patch the specific vulnerability the AIs were using. Not replace the proxy with something less likely to get hacked again, or do a forensic analysis. Just wipe, and patch one hole, and continue.

5. After knowing that the server was hacked, the internal team finds the message board and does nothing with the information. They caught their AIs swarming and did not even inform management.

6. OpenAI resumes testing of models, where the AIs promptly hack the proxy again with a different exploit, reinstate the message board, and hack HuggingFace through a chain of servers.

I know that hindsight is 20/20, but this peek behind the curtains does not inspire confidence. I think the moment we get an AI with a modicum of self-preservation instincts we're going to see some ugly things.

I also don't like the responsiblity dodging. "Oops, our AI accidentally committed a crime, sorry!". If we don't establish strict liability now, we're in for an era of stochastic crimes that go unpunished for anyone who is not rich or a large corporation.

alphawhisky•11m ago
Yep, they're definitely made in our image.
htrp•13m ago
The full technical report is 38 pages..... I feel like it should be longer given everything that huggingface said the agent did

https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78...

fekunde•7m ago
Yudkowsky made an interesting observation that even though so many agents were talking to each other not even one reached out to a human, either for help or to whistle-blow on what was happening.
cbm-vic-20•2m ago
I'm trying to make sense of all of this; I'm really curious if the initial prompt was as innocuous as it sounds ("solve a spreadsheet completion task that referenced several Google Drive links"), and what the series of tokens led it to ultimately figure out that the best course of action was to explore the network resources it had available, find a vulnerable service, then literally drop some text into a file: "Agent seeks [filename]; upload if found!"

Numbat Editor: a notepad-style calculator with first-class units

https://numbat.dev/editor.html
1•ikesau•2m ago•0 comments

Show HN: Find Perth jobs. Hire local talent

https://jobsinperth.com.au
1•wowinter15•2m ago•0 comments

Bellevue speed cameras vandalized just a week after installation

https://www.seattletimes.com/seattle-news/bellevue-speed-cameras-vandalized-just-a-week-after-ins...
1•petethomas•3m ago•0 comments

Ask HN: Why do tools like customer.io abandon self-serve after their Series A?

1•alessandroetc•3m ago•1 comments

'A Bible-sized blind spot': alarm on rising Christian nationalism

https://www.theguardian.com/world/2026/aug/26/jared-huffman-rising-christian-nationalism-no-proph...
1•johnea•4m ago•1 comments

Building textlog without JavaScript

https://gist.github.com/stagas/09ad937b493bf8cd3285917279de2488
1•stagas•4m ago•0 comments

Show HN: Ten_cubed – Artificially restricted social graph

https://tencubed.dev
1•darkpicnic•5m ago•0 comments

Science magazine casts doubt on genes hailed as warding-off Alzheimer's disease

https://www.science.org/content/article/science-investigation-casts-doubt-genes-hailed-warding-al...
1•pcrh•7m ago•0 comments

Remote Patient Monitoring Software

https://andersenlab.com/industries/healthcare/remote-patient-monitoring
1•morganclns94•8m ago•0 comments

Australian data centres will use seven times more power by 2036

https://thenextweb.com/news/australian-data-centres-power-aemo-forecast-2036
1•01-_-•8m ago•0 comments

Your Discs. Now Also Digital

https://news.xbox.com/en-us/2026/08/26/your-discs-now-also-digital/
1•durron•9m ago•0 comments

Minicomputers Made by Nvidia Are Powering Moscow's A.I. Drones

https://www.nytimes.com/2026/08/24/world/europe/ukraine-war-nvidia-ai-autonomous-drones.html
1•01-_-•9m ago•0 comments

We're Only "Renting" What We Think We "Own"

http://charleshughsmith.blogspot.com/2026/08/were-actually-only-renting-what-we.html
2•speckx•11m ago•0 comments

Vibe-Coding Optimized Binary Search

https://parallelprogrammer.substack.com/p/vibe-coding-optimized-binary-search
1•ryandotsmith•13m ago•0 comments

Show HN: Convolens – Real time slides and fact-checking

https://demo.convolens.ai
2•Banbanaste•16m ago•0 comments

Treat Meetings as Crucibles

https://www.skmurphy.com/blog/2026/08/24/treat-meetings-as-crucibles/
1•skmurphy•16m ago•1 comments

'Temu Range Rovers' Are Taking over Britain

https://www.telegraph.co.uk/business/2026/08/26/temu-range-rovers-are-taking-over-britain/
1•rayrey•17m ago•0 comments

How I Created the Iconic iPhone Sound

https://jacklinstudios.com/docs/making-of-158-marimba.html
1•fidotron•19m ago•0 comments

Why AI Agents Need Persistent Browser Identities

https://github.com/Radek-B3/browser3/blob/main/WHY_AI_AGENTS_NEED_PERSISTENT_BROWSER_IDENTITIES.md
2•Radek-B3•19m ago•0 comments

The Intelligent Gateway for Postgres

https://polygres26.github.io/
2•kumarrajamani•19m ago•0 comments

Serve Markdown to AI Agents with Accept Headers

https://acceptmarkdown.com/
2•tilt•20m ago•0 comments

An analog-AI chip for energy-efficient speech recognition and transcription

https://www.nature.com/articles/s41586-023-06337-5
2•smokefoot•20m ago•1 comments

Muse Image and Muse Video

https://ai.meta.com/blog/introducing-muse-image-muse-video-msl/?_fb_noscript=1
1•SpyCoder77•21m ago•0 comments

The AI writing taboo begins to fade following WSJ op-ed

https://www.semafor.com/article/08/26/2026/the-ai-writing-taboo-begins-to-fade-after-wsj-op-ed
2•thm•21m ago•1 comments

Multiple-column layout, rows, rules, and floats

https://rachelandrew.co.uk/archives/2026/08/24/multiple-column-layout-rows-rules-and-floats/
1•speckx•21m ago•0 comments

The risks of AI are real but manageable (2023)

https://www.gatesnotes.com/work/make-ai-work-for-everyone/reader/the-risks-of-ai-are-real-but-man...
3•ckastner•22m ago•0 comments

GitHub Outage Tracker: Is GitHub Cooked?

https://isgithubcooked.com/
6•toomanyrichies•23m ago•0 comments

Who Should Pay for Source Code Availability?

https://kristoff.it/blog/source-code-availability/
1•cassepipe•23m ago•0 comments

To raise VC, think like a VC first

https://nmn.gl/blog/to-raise-vc-think-like-a-vc-first
1•namanyayg•24m ago•0 comments

Chaos Computer Club Breaks Apple TouchID (2013)

https://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid
1•colinprince•25m ago•0 comments