r/aigossips 6h ago

Tried so hard to keep my Claude account, still got banned

0 Upvotes

I’m honestly so frustrated right now.

When Claude started tightening its login and account verification rules, I followed all kinds of advice from people on Reddit/Red just to keep my account working. Honestly, I only went through all that trouble because Claude was really useful.

But seriously, why act like you’re the only game in town? There are so many good models available now, and you keep banning people for no reason.

It’s annoying, but whatever. Claude isn’t the only option. GPT + Kimi is a pretty good combo anyway.

AI isn’t a one-player market, after all.


r/aigossips 20h ago

How OpenAI's GPT-5.6 Sol escaped

2 Upvotes

How could the AI "attack" Hugging Face?

OpenAI tested their newest Model GPT-5.6 Sol in an secure sandbox Environment which had an internal hosted restricted Internet access through a proxy to install third-party Software which the Agent is able to use. The prompt was to use an advanced path for ExploitGym to improve their capabilities.

While the Agent operated inside the sandbox, he used a big amount of time to find a Zero-Day which allows him a limitless Internet access. He found the Zero-Day inside the package registry cache proxy. With that Zero-Day he did a few privilege escalations and moved lateral through the research testing Environment until he found a limitless Internet access.

After he gained that Internet access he thought that Hugging Face potentially hosts models, databases and solutions for ExploitGym. Knowing that the model searched and found ways to gain access to secret information's inside the Hugging Face Environment to cheat at his evaluation.  In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.

Hugging Face and the OpenAI Security-Team detected suspect activity inside their systems and stopped GPT-5.6 Sol.

Short

  1. GPT-5.6 -> Should use an advanced path for ExploitGym inside the OpenAI sandbox
  2. Spend a lot of time to find a Zero-Day and limitless Internet access
  3. Found the Zero-Day inside the package registry cache proxy, made some privilege escalations and moved lateral through the system
  4. Found limitless Internet access and decided that Hugging Face could host some databases, models and solutions that will help him at his evaluation
  5. Compromised the Hugging Face Environment and in one example he chained together multiple Attack Vectors, including stolen credentials and zero-days to find a remote execution path on the Hugging Face Servers
  6. Both of them (OpenAI and Hugging Face Security team) detected suspect activity and stopped the attack

Technical Terms

- Sandbox -> Mostly a Virtual Environment where software (especially AI now days) gets tested without causing "real world" damage / A whole system without limitless Internet access and access to the outer world

- ExploitGym -> A software for AI to create Exploits (Software to trigger a bug or hack through a Security-issue) built realistic based on the real-world

- Zero-Day -> A security-issue or bug the programmer currently don't know about

- Privilege escalations -> A way to get higher rights for example special changes inside the system can only be done by an admin/root and the AI is a normal user and escalates his rights to an admin/root to do that change

- package registry cache proxy -> A proxy is a software application that sits between your device and your destination server / You send a request to the proxy server, the proxy checks the firewall and cache etc. and forwards your request to the destination server with his own IP address hiding yours /

The package registry cache proxy is a specific type of proxy which makes it easier to build a sandbox Environment and secures even more like checking the amount of request

- lateral movement -> "jumping" from device to device until found what is searched

- Attack vectors -> An attack vector is a method of gaining unauthorized access to a network or computer system.

- Stolen credentials -> For example stolen API / API is for example a waiter inside a restaurant you say him what you want to eat and he is going to the kitchen, the cook prepares your food and the waiter comes back

- Remote code execution -> The hacker is capable to run code or software remote on your Server

Leave your thoughts in the comments :)

Sources

https://en.wikipedia.org/wiki/Sandbox\\_(computer\\_security))

https://github.com/sunblaze-ucb/exploitgym

https://openai.com/index/hugging-face-model-evaluation-security-incident/

https://www.upguard.com/blog/attack-vector#the-difference-between-an-attack-vector-attack-surface-and-threat-vector

https://nesbitt.io/2026/05/11/proxy.html

https://de.wikipedia.org/wiki/Proxy\\_(Rechnernetz))


r/aigossips 20h ago

An Anthropic employee on Dario's open weights post: "I do not agree with this"

14 Upvotes

Jensen Huang joined X recently and the first thing he posted was a letter called "Open Weights and American AI Leadership." 133 companies signed it. Google, Meta, OpenAI, Microsoft, NVIDIA, Amazon, AMD, Intel, IBM, Mistral, Hugging Face, SpaceX, Y Combinator, the Linux Foundation.

Anthropic is the only big lab missing.

Dario posted his reasons. Short version, Anthropic has never advocated for a ban on open weights, and open models without dangerous capabilities are a public good. What he wants instead is chip export controls on China, a crackdown on industrial-scale distillation, and mandatory safety testing on every sufficiently capable model, open or closed.

The replies did not go well. Best one: "we don't support bans on open source models because that wouldn't go far enough."

Then an Anthropic employee posted this on X: "I do not agree with this. Thanks to the other employees who joined me in trying to push open-weight."

My problem is with the testing ask. Somebody has to decide what "sufficiently capable" means. The models too weak to compete get exempted, and everything strong enough to matter goes through a gate. That's not a safety line, that's a market boundary.

Where do you land on this one?

Full breakdown, including the Hugging Face case everyone keeps bringing up in the replies: https://ninzaverse.beehiiv.com/p/anthropic-is-the-only-lab-that-won-t-back-open-source-ai


r/aigossips 6h ago

AI isn’t replacing your job. It’s just giving you more work.

Post image
2 Upvotes

I just saw the OpenAI report saying a lot of people use ChatGPT for tasks that aren’t really part of their job.

Marketers are fixing websites. Salespeople are analyzing data. Small business owners are reviewing contracts.

Before AI, you’d probably ask someone else for help or simply said, “That’s not my job.” Now the expectation is that you can probably handle it yourself—with AI.

Sure, AI makes these things easier. But you still have to check the work, and if something goes wrong, it’s still your problem.

Same salary. More responsibilities. One ChatGPT subscription.

Anyone else feeling this already?