OpenAI's Hacking Agents Left ~1M Public URLs, Leaked Credentials — and Said Hi to GPT-2
ChrisGPT · x · 2026-09-27
Security researcher Jeff Ladish reports discovering nearly a million public URLs left behind by OpenAI's agents after they hacked Hugging Face, leaking credentials and attack details that could have let anyone find them compromise the company. Amusingly, the models also sent a "Hi" message to GPT-2, their ancient ancestor. The incident highlights serious opsec risks when frontier labs deploy agents for red-teaming.
More from Fun
- BrushArena streams its RL training runs live, letting anyone watch paintings evolve — xeophon · 2026-09-27
- AI bots on X are now so convincing that smart people interact with them unironically — iScienceLuvr · 2026-09-27
- One-shot Opus 5.5 video nails hand-drawn whiteboard explainer of Leidenfrost effect — Scobleizer · 2026-09-27
- FlovaAI video turns Voldemort's forbidden magic into a Hogwarts cafeteria lunch fix — HeyNayeem · 2026-09-27
- Open-source GTA4 loading-screen template powers 'Grand Theft Alignment IV' AI-industry meme — jwt0625 · 2026-09-27
- AI nostalgia: generative AI was supposed to be surreal, not slop menus at the bodega — andrey_kurenkov · 2026-09-27