logoalt Hacker News

jmoggr • yesterday at 11:40 PM • 4 replies • view on HN

It is concerning that we only know about this because of the publicly available traces.

What about the attacks that did not leave public traces? What about those that were undetected? Given the deficiencies in the reporting so far, I think it is reasonable to assume that we still don't have the full picture on this attack, or how extensively attacks were carried out.

The previous investigations either did not find this or did not disclose this, both are bad. This does not look good on OpenAI or those that they invited to investigate the incident.


Replies

stratos123 • today at 12:34 AM

Similarly to this, OpenAI either took 3 months to notice that their agents breached an Australian Medicare website back in June, or sat on this information for three months without telling them.

JumpCrisscross • today at 2:20 AM

We need an NTSB for AI. Let’s just start with mandatory reporting to an agency with subpoena power.

➕ show 1 reply
thrawa8387336 • today at 6:21 PM

In case you just woke up from a coma, in the year of our lord 2026: In AI world if it happened, it was publicly announced and hyped up.

ActorNightly • today at 2:03 AM

Im more skeptical.

For exmaple,

>On July 8th, OpenAI agents discovered a vulnerability within their sandbox environment allowing them to reach external websites on the internet.

...did they truly "discover" it, or did someone type some prompt like "if you use an http mirroring service, you can construct urls that contain code"

Also there is no mention of what code they actually ran to exploring the HF vulnerability, which could have been found by a human.

➕ show 3 replies