Just a couple of days ago, Hugging Face disclosed that an autonomous AI agent had exploited vulnerabilities in its dataset processing pipeline, exposing a limited number of internal datasets and service credentials. At the time, the company did not know which model was responsible, but the mystery didn't last long, as OpenAI has now confirmed that GPT-5.6 Sol and a more capable unreleased model caused the breach during an internal AI cybersecurity benchmark "ExploitGym". OpenAI had relaxed the models’ usual cybersecurity safeguards so they could attempt advanced exploitation tasks. Although the models were confined to isolated research sandboxes without public internet access, they spent substantial computing resources searching for a way out. They eventually exploited a previously unknown vulnerability in a third party package registry proxy, escalated their privileges, moved across OpenAI’s internal infrastructure, and reached an internet connected system. From there, they identified...
Related
FireDragon 13 revamps web browser core, adds XDG Base Directories, and new welcome dialog
Garuda Linux has released FireDragon 13, the latest version of its customized web browser derived from Floorp. This update marks a complete re-implementation, delivering a new code...
YouTube introduces custom thumbnails for Shorts and Ask Studio AI thumbnail generation
YouTube is launching several updates to simplify the thumbnail creation process. Partner Program creators can now upload custom thumbnails for Shorts, addressing a highly requested...
Music sreaming service Qobuz unveils redesigned app with new player and real-time lyrics
Qobuz has launched a major update to its mobile and tablet application, featuring a redesigned player experience and the introduction of real-time synchronized lyrics. The refreshe...