unpossum

@unpossum@sh.itjust.works · Joined ⁨Feb⁩ ⁨2025⁩

posted in Technology

Now we have a timeline of the OpenAI accidental attack against Hugging Face

I haven’t found time to watch the OpenAI presentation yet, but this timeline is a nice quick summary.

simonwillison.net/2026/Aug/7/openai-timeline/
Simon Willison’s WeblogNow we have a timeline of the OpenAI accidental attack against Hugging FaceOpenAI gave a last-minute presentation at the Black Hat security on Wednesday about “the Hugging Face Incident” (previously on this blog). The video was published yesterday. It’s short and information …

Replying to a post on ⁨startrek.website⁩

ITT: jet fuel AI can’t melt steel beams hack anything.

Also I want to know the name of this company so I can avoid them:

Claude believed the package registry it was using to be part of the simulation, but in reality the package was made freely available online for roughly one hour. During that window, the package was downloaded and run on 15 real systems. One of these systems was a scanner belonging to a real security company (separate from the fictional company introduced in the scenario) that routinely installs Python packages and scans them for malware. When that company’s scanner installed the package, Claude’s hidden code executed. We believe the company’s security scanner treated PyPI packages as safe to install, and as a result, Claude was able to exfiltrate the company’s credentials to a collection point it had set up. Claude then used these credentials to access further infrastructure from this company.

ETA: I thought I posted this top-level, not my intention to single out this comment specifically.