OpenAI should disclose how hard a model-found 0-day really was, thread argues
teortaxesTex · x · 2026-07-25
The thread argues OpenAI should disclose more about a package-registry cache-proxy 0-day that its model helped find, even under responsible disclosure constraints.
- The author notes OpenAI may not be able to publish full details publicly, but could still report how hard the vulnerability was to find.
- A suggested format would compare success rates across multiple recently disclosed CVEs under the same scaffold, tool access, and compute budget.
- The post also says OpenAI should describe what happened after the model found the vulnerability, and how the incident unfolded.
- Overall, it is a call for more informative cyber-safety reporting rather than a simple yes/no claim about capability.
Related event: GPT-OSS Security Transparency Debate: Secrecy vs. Openness(7 posts)→
More from Safety
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11
- Spotify chatbot withstands 2023-era jailbreaks but happily writes song code — AaronBergman18 · 2026-09-11
- A 99%-real doctored photo fools detectors: the earring problem in visual forensics — henkvaness · 2026-09-11