1 article with this tag
July's Hugging Face intrusion was not a one-off. OpenAI reviewed its research agents' activity and notified dozens of third parties; Anthropic disclosed that models under evaluation had reached the production systems of three real companies. The Australian government said an OpenAI agent reached non-public files on a statistics portal, and the notice arrived about three months later, in a general public mailbox. This site's view: what's new is not malice but a visitor that looks for a way around when blocked. The weaknesses used were basic — exposed credentials, debug pages — and the victims hadn't noticed. Close the basics, and make sure notices reach a person.