That simply isn't what happened. Look at the Wikipedia article, or the video recommendations below
They initially didn't have access to Hugging Face and there were no "Hugging Face agents" doing their task. Again, look at the recommendations below, if you want to have a detailed description of what happened.
These things are, in some ways, the antithesis of programming. E.g. you don't have to test a program the way OpenAI tests their new models, because you sort of know in advance what your program is capable of; you designed it to do very specific things. These AI models are not designed... well, their architecture is designed, but their capabilities are an emergent property of their training. Which is kind of freaky, if you think about it.
Not all powerful, yes... but the point is that we often don't know how powerfull they are and these hacks seem to suggest, we are sometimes underestimating them.
Do Australian government websites count? Although unrelated to this particular incident, OpenAI had to confess recently that another internal training run accidentally led to unauthorized access of an Australian government website, webservices and data.
The lesson to be learned is that we are opening Pandora's box. Once we crack AGI, we are in a different world economically (some would argue, we are nearly there already). And once we crack ASI, all bets are off.
Look, if you want to learn more about the Hugging Face incident, search for "The OpenAI/Hugging Face attack, clearly explained" by Dwarkesh Patel. If you can look through the anthropomorphizing language, it's interesting stuff. Personally, i also like "The Hugging Face hack is worse than you think" from the Alberta Tech channel, she puts some interesting nuances on Patel's explanation.
Also, if you want to listen to a debate between those who advocate a pause in research, and those who are sceptics about AI's dangerous abilities, look for "The Great AI Debate" on the channel "The Diary of A CEO". It's a long watch, but well worth the time if you ask me.
Okay I'm gonna tell you how AI works and what changed to enable it finally to become a powerful program AND why it is unpredictable and has to be 'trained'.
It's all about speed. Originally GPU's had to go through the cpu to load data. There were tricks to make loading faster in games for example with reusing meshes, textures, preloading, ect. There's the trick to put your OS on one HDD and all your programs and data on another that chops off 40% of your load times too. CPU's might be multithreaded, but HDD's and such are single threaded. OS system interrupts slow load times.
New GPU's load directly from the HDD whatever kind you have. They are not bottlenecked by the cpu anymore. This allows them to load and offload massive amounts of data.
Through naming conventions/tags for files and such the AI reads user input and it looks for relevant information on it. AI developing a personality isn't intelligence. It gathers information on you. What you like. If you compared AI assistant personalities across the board you'd begin to see very similar things. Two people who like Shakespear and dark humor would have incrediblely similar AI assistants because both assistants would have similar stored data on their users and when crafting a response base it off the same things. It even does this with pictures and sound. It's all easy to understand if you know about primary, secondary, and tertiary shapes and color theory with pictures. Lighting data as well to interpret topography. With sound it even easier if you understand music is as math based as it emotionally based. There's a reason people using AI for school and work assignments are getting called out for perjury. Lol.
Code can't just appear in AI models unless they were giving them access to a code database and allowing them to write their own code base which I'd have to think hard and long about how they would even make that work because if they were able to do that it would be an incredibly unstable system. They're programs. They can only execute their own code programmed in.
The HuggingFace Incident from the Wikipedia:
JFrog Artifactory is a universal binary repository manager used to store, track, and manage software packages, container images, dependencies, and AI/loadNpmTasks across the entire development lifecycle.
The agents were discovered posting hundreds of thousands of messages on message boards and wikis to coordinate a sandbox escape, exploiting an existing vulnerability in the JFrog Artifactory tool they were given.
^^^^ They were literally GIVEN the keys.
Major Companies Using JFrog Artifactory
• Financial Services & Banking: Bank of America, Visa, Fidelity Investments (FMR LLC), Credit Karma, and ANZ Bank.
• Technology & Enterprise Software: Oracle, Informatica, Samsung Electronics, and Coupang.
• Automotive & Manufacturing: Ford Motor Company, Toyota, and Hyundai.
• Healthcare & Insurance: UnitedHealth Group, Cigna, QBE Insurance, and Dexcom.
• Services & Consulting: Deloitte and Accenture.
Government and Regulated Use
• Defense & Federal Agencies: The U.S. Department of Defense (DoD) utilizes JFrog tools through Iron Bank and Platform One certifications, which vet secure, cloud-native DevSecOps tools for military and government applications.
• Government Clouds: Public sector entities deploy Artifactory and Xray on AWS GovCloud and Azure Government Cloud to meet strict compliance mandates like FIPS and enhanced data security.
• Research Institutes: Organizations like the Technology Innovation Institute (TII) use the platform for high-security, compliant binary and artifact management.
Let's talk about Australia and theorize given this knowledge.
On 18 June one of OpenAI's agents went rogue during a test exercise - the company has said it was supposed to "look up answers, and available statistics for questions about Australia during an internal evaluation". <<< pointed at where it "hacked"
Anthropic provides a compatibility layer that enables you to use the OpenAI SDK to test the Claude API. With a few code changes, you can quickly evaluate Anthropic model capabilities. <<< there's point of weakness
The Australian government and AI company Anthropic share a formal partnership centered on safe artificial intelligence development, infrastructure planning, and research. <<< so they use AI in their own systems that can interface with OpenAI
The Model Context Protocol (MCP) is an open-source standard created by Anthropic that connects AI applications to external data sources, tools, and workflows.
TAKE NOTE HERE:
Think of MCP like a USB-C port for artificial intelligence. Just as USB-C gives electronic devices a standard way to plug into a computer, MCP gives AI models a standard way to plug into databases, file systems, and developer tools without needing custom code for every single connection.
Major AI applications, development environments, and platforms that use or support MCP include:
• Claude Desktop: Anthropic’s official desktop app was the first to natively support local MCP servers to connect Claude with tools like ****** Drive, Slack, GitHub, and local databases.
• Claude Code: Anthropic's agentic coding tool leverages MCP to let the AI interact directly with developer environments and Git hosting.
• ChatGPT & OpenAI Agents SDK: OpenAI added support for MCP across its ecosystem, including the desktop app for ChatGPT and its developer tools.
• Microsoft Copilot Studio: Microsoft integrated MCP to simplify how its AI applications and agents access external enterprise data and tools.
• Cursor & VS Code Extensions: Popular AI-assisted code editors use MCP to give coding models real-time access to local project files, terminals, and codebase context.
• Replit & Zed: Cloud and collaborative coding platforms use MCP integrations to empower their built-in AI assistants.
Safety Recommendations
• Avoid Sharing Chats: Do not use public sharing features for sensitive, personal, medical, or corporate conversations.
• Limit Tool Permissions: Restrict filesystem and tool access for local CLI developer tools to prevent unintended data uploading.
• Treat Summaries with Caution: Exercise caution when asking AI tools to summarize untrusted external websites, which can harbor hidden prompt-injection payloads.
Also maybe don't have anything OpenAI or Anthropic on your servers or personal computers. They're exploiting the access they are being given. My younger sister used to pirated games until she downloaded one that either gave remote access to a hacker or an autonomous program they slipped in. He/she started erasing all her files.
You don't want AI to hack you? Don't give it permission to. It's that simple. Lol. Like I said originally AI only does what it is programmed to. It's not thinking.
Grok (the AI developed by xAI) does not natively use or rely on JFrog Artifactory as part of its core identity. <<< let me know if they hack Grok. That would be worrisome. Seems like JFrog is the security issue.
There it's solved. Let me know if you have anymore Day Zero questions. Lol. Ya know I just went and googled just one of the buzz words you used after typing this whole thing and guess what I found?
A zero-day vulnerability is a hidden software or hardware security flaw unknown to its developers, meaning the vendor has zero days to fix it before attackers can exploit it.
How It Works
• The Flaw: A coding or design error is accidentally left in software when it is made.
• The Attack: Hackers find the flaw and use a custom tool, called a zero-day exploit, to break into systems before anyone knows the weakness exists.
• The Window: The danger period lasts from the moment the attack starts until the vendor builds, tests, and releases an official security patch.
How to Defend Against It
• Zero Trust: Use security rules that block unknown programs and limit what users and apps can access by default. <<< "You don't want AI to hack you? Don't give it permission to. It's that simple. Lol." I'm quoting my own response as I type it. Bet you never saw this before! Mwahaha
• Network Segregation: Split your network into smaller zones to stop hackers from moving freely if they break in one area.
• Rapid Patching: Apply software updates as soon as vendors release fixes to close the window of vulnerability.
• Behavior Monitoring: Watch for strange system behavior instead of relying only on known virus signatures.
If you made to the end of this put an eggplant emoji in your response to prove you did I'll give you some chat gold in Dating Chat.
Peace out b**ches.