this post was submitted on 05 Aug 2026
49 points (93.0% liked)

Technology

87515 readers
2851 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] merde@sh.itjust.works 14 points 2 weeks ago (1 children)

According to OpenAI, one of its GPT-5.6 Sol agents was being evaluated on a platform called ExploitGym, which benchmarks large language models by asking them to write proof-of-concept security exploits for known vulnerabilities. Normally, ExploitGym is designed to be a closed ecosystem for proof-of-concept testing only, and AI agents shouldn’t have access to the internet while being evaluated.

But this agent found a zero-day vulnerability in a package registry tool called Artifactory, then used it to gain access to the web. From there, the OpenAI agent gained access to Hugging Face’s company systems using publicly exposed credentials across four separate services. It went on to spend two days inside the company’s internal systems, managed to secure root access to several production servers, and even enrolled 181 attacker-controlled devices into Hugging Face’s corporate network. 

😮

[–] CheeseNoodle@lemmy.world 8 points 2 weeks ago

This sounds less like a new exploit or anything to do with AI and just a rewording of the age old problem of companies storing the fucking passwords in plain text and hoping no one notices.

[–] treadful@lemmy.zip 8 points 2 weeks ago

the agent was operating on instructions that reduced cyber refusals to successfully evaluate the model