Top
Best
New

Posted by artninja1988 14 hours ago

Responding to the next frontier of critical cyber capabilities(openai.com)
172 points | 173 commentspage 4
throwaway613746 8 hours ago|
[dead]
bakugo 13 hours ago||
This marketing stunt must've been really successful in their eyes, because they're milking it as much as they can.
petesergeant 13 hours ago|
It's nice to cynically call this a marketing stunt, and terrifying to consider that they might just in fact be moving fast and breaking things.
TrueDuality 13 hours ago||
Ah yes let the FUD continue. This is a real problem but so far not nearly as severe as any of the marketing has made it out to be to the overall detriment of everyone including these companies announcing these scary capabilities. These announcements always included half hearted attempts at security layers which has now been demonstrated to benefit attackers more than defenders.

I wish I had a real solution to this beyond a dark age of the Internet where people have to finally come to terms with the general poor quality all modern software tends to normalize at.

hbn 13 hours ago||
The recent Hugging Face incident did not seem like FUD to me
Tiberium 13 hours ago|||
The fact that HF had to resort to using GLM 5.2 to analyze the logs/payloads makes it look legitimate, at least for me. They would not say that they hit guardrails with the frontier US models when defending if this was an obvious PR stunt.

https://huggingface.co/blog/security-incident-july-2026

> When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

devin 13 hours ago||
It depends on which side you're viewing this from. From oAI's it could be a publicity stunt or a request for regulation, and from HF's side they point out that they needed open models to get to the bottom of the issue, and that regulation will potentially lock us into a bad place.
TrueDuality 12 hours ago|||
You should go read the actual technical reports of the incidents and the follow on reports about the capabilities of smaller models in similar kinds of environments. This isn't new. The things exploited are still pretty basic in old and poorly maintained software or in gaps in architecture that were intentionally poked against security policies.

Are the findings valid? Yeah they're still doing security and they're still finding real zero-days. I think the internet is going to be bleak not because these models can ALL do basic security research but rather that the baseline quality of all deployed software is so low.

mephux 13 hours ago||
We all know this is propaganda to get a gov bailout or to slow down competition with regulations right? If this was an issue companies that did red team engagements would have been regulated long ago. There is no regulations on companies that actively exploit products, companies and services for money. They could all be bad actors.. yet, no regulations.. its all nonsense. If it's important.. don't connect to the internet.. there, you are good.. like if you don't want to OD on heroin.. don't do the heroin.
jackb4040 11 hours ago|
Don't let the downvotes get you down. We are right, and as these companies get more desperate the shrinking minority that still wants them to succeed will only get louder.
reasonableklout 10 hours ago||
Do you think calls for regulation are only coming from people who want the frontier labs to succeed?
bearjaws 13 hours ago|
These AI companies have found their #1 marketing piece and just beating it to death.

The reality is if they cared about security at all they would provide a way for me to credential myself against my companies environment so I can use the AI on it to improve our security.

Tiberium 13 hours ago|
Isn't this literally what https://chatgpt.com/cyber and http://openai.com/form/enterprise-trusted-access-for-cyber are for?