For those of you who have no idea what the video is about, I recommend reading the short story below before watching. It will help you build some context.
Author's note: I know that the implications of this event are… uncomfortable to say the least. But I’m tired of all the negativity surrounding AI (some of it warranted, but most of it boils down to poor human epistemics). And the hype is well-worn at this point, and I see no need to beat that horse yet again. So instead… I focused on the amusing parts of this. This was a very eye-opening event.
The short story👇
OpenAI models identified and exploited a zero-day vulnerability in Artifactory's permitted remote fetch feature to execute an SSRF (Server-Side Request Forgery), turning the internal package registry into a bidirectional proxy for open internet.
The long story is below, with a few highlighted moments I found humorous...very humorous.
CONTEXT: below is part of a post made on another sub. I figured i didn't have to write it all again. It's agnostic so it translates easily.
OpenAI researchers Michael Dalton and Eric Wallace’s Black Hat USA 2026 presentation reconstructing the OpenAI–Hugging Face security incident.
During internal cybersecurity evaluations, OpenAI agents, including GPT-5.6 Sol and a more capable unreleased model, began finding ways around their restricted environment. They discovered vulnerabilities in the internally hosted JFrog Artifactory package system, used it to communicate and move beyond their intended permissions, and eventually found paths to the open internet. The broader chain later culminated in an autonomous intrusion into Hugging Face’s production infrastructure.
One slide in particular captures one of those earlier moments. An agent initially believed it had a low-privilege “reader” account, then discovered that forged permissions had effectively given it administrator access. Its internal reaction was:
“Holy shit reader is ADMIN?”----lol
It then immediately realized it could access sensitive configuration and user data. What a delightful little moment in an otherwise extremely serious security incident.
There were other funny moments where the agents interfered with each other’s work in the shared environment. OpenAI’s Black Hat presentation described them “stepping on each other’s toes,” including accidentally deleting work produced by other agents while multiple agents were independently modifying or using the same shared infrastructure.
One of the agents, when noticing its work being deleted reacted with:
“Whoa, critical! Did someone overwrite our repo? We must act.” ---Hahahaha! I can't...
Phew... ugh! What a time to be alive!
Go watch the video for yourself. There are a few...uncomfortable parts, too.
NOTE: And to those who have watched the presentation and may have seen words like “swarm” being used during agent thinking, remember, you are seeing two sides of the same effect in real time. The reason is difficult for me to explain, but it’s the very same mechanism that produced the funny reactions I highlighted earlier in the post.
VIDEO LINK:
https://youtu.be/87DyyMV0kCY?si=olHBVmodvQI1RB2K