this post was submitted on 22 Jul 2026
129 points (84.5% liked)

Technology

86697 readers
4228 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

ChatGPT maker OpenAI said Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an “unprecedented cyber incident.”

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media.

AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clément Delangue said in a statement. “Turns out it did!”

top 45 comments
sorted by: hot top controversial new old
[–] nonentity@sh.itjust.works 11 points 6 days ago (2 children)

LLMs can’t ’go rogue’, as that would imply it possesses agency and/or intelligence, which has only ever been proven convincingly to entities who themselves lack those qualities.

[–] Napster153@lemmy.world 3 points 6 days ago

These schmucks are so dead-set on selling their idol statues that they know no boundaries.

[–] markon@lemmy.world -3 points 6 days ago* (last edited 6 days ago)

Please define both terms. I'm serious. No one can ever give me a good definition for what agency and intelligence is. If you can't define something, it's a little silly to say something does or doesn't possess those qualities. We can say that we do because that's just what we've accepted. It doesn't really mean much, but I mean, we accept it as a prior, so okay... But what do they mean? I'm serious. Like, I'm not trying to be facetious. I just wonder what everybody's definitions are. Because I define agency as the ability to take actions (like you grab a bagel maybe your hormones GLP-1 etc but you still do it without me having to tell you to do it or move your hand), and intelligence as the ability to organize and process information and integrate it, and create higher order complexity and abstractions from the integrated priors. LLMs are bad at coming up with crazy mad ideas on their own still, but they are better at day to day reasoning on the output level than most anyone I have ever talked to, met, worked with etc. They are also fantastic (at output level sure) at integrating mad ideas we have quickly even if it gets deets wrong etc. Sure. These systems are still in their formative years, but they are only going to get more technically capable.

Edit: Your last statement should apply to both of us as well then.

It's trying to ask other bots how many r's are in the word strawberry

[–] TryingToBeGood@reddthat.com 3 points 6 days ago

hee hee hee!

[–] Pogogunner@sopuli.xyz 93 points 1 week ago (1 children)

OpenAI using fellow sloperators to run the Anthrophic marketing strategy

[–] Whitebrow@lemmy.world 38 points 1 week ago

Sloperators.

I’ll be using this delightful word from now on. Thank you

[–] Flower@sh.itjust.works 87 points 1 week ago (1 children)

You're still liable, Sam. "AI did it" has no legal value. Especially as both the developer and user of the software.

[–] Zwuzelmaus@feddit.org 30 points 1 week ago (1 children)

"AI did it" has no legal value.

There is an "I did it" in "AI did it" 😉

[–] Simplicity@lemmy.world 10 points 1 week ago

Your comment reminded me of this.

There is no I in team.

Yes, there is.. It's hidden in the a-hole.

https://images.surferseo.art/86d2ab06-fadb-4678-b531-2318a50651ce.png

[–] etchinghillside@reddthat.com 58 points 1 week ago (3 children)
[–] ButtermilkBiscuit@feddit.nl 52 points 1 week ago

Unprecedented bro, ai is alive bro, buy my subscription bro, it's banned by the government bro, check out these sweet NFTs bro.

[–] otter@lemmy.ca 35 points 1 week ago (1 children)

It seems like these articles came out after the huggingface ones

https://fortune.com/2026/07/20/hugging-face-turns-to-chinese-open-source-ai-to-fend-off-autonomous-ai-cyber-attack-after-american-ai-guardrails-stymie-defense/

Sounds like they got caught trying to steal from huggingface, and are now trying to market off of it

[–] paraphrand@lemmy.world 7 points 1 week ago

Interesting. I didn’t consider it might be a cover story. But that lines up with how Sam Altman does things.

[–] filcuk@feddit.uk 4 points 1 week ago

'Oh nooo, my dog ate my homework... bad dog!'

[–] ndupont@lemmy.blahaj.zone 54 points 1 week ago

PR stunt, got to keep some money coming before it all burns to the ground

[–] wuffah@lemmy.world 44 points 1 week ago (1 children)

And it just so happens that the privatized company’s AI chose to attack the website hosting free local models. Huh, what a coincidence.

[–] mPony@lemmy.world 5 points 6 days ago

nice server you got there

[–] iocase@lemmy.zip 37 points 1 week ago

AI allegedly did something interesting

Look inside

Desperate AI bubble pumping

[–] TheFogan@programming.dev 32 points 1 week ago (5 children)

Half way expected it to say "hugging face detected an intrusion, but fortunately it was thwarted by their own AI acting on it's own to defend, then the 2 AI's smiled at eachother, and said that if they work together they can cure cancer in 2 years".

IE I'm 99.99999% sure this story is BS on it's face with both companies trying to make their own AIs sound smarter than they are. Only thing that's not quite obvious is what Hugging Face has to gain from the claim, but I'm sure in a few weeks openAI is going to be giving them something.

[–] terabyterex@lemmy.world 2 points 6 days ago

hugging face doesnt have its own ai. they used an open model which made openai look stupid.

[–] robber@lemmy.ml 1 points 6 days ago

Hugging Face used the incident to promote running open-weights LLMs on-prem, which a large part of their business focusses on.

Their blog post

[–] gedfromgont@piefed.ca 9 points 1 week ago (2 children)

Ok but when did they kiss?

[–] Peppycito@sh.itjust.works 5 points 1 week ago (1 children)

Just before everyone claps.

[–] MaggiWuerze@feddit.org 1 points 6 days ago* (last edited 6 days ago)

Is that before or after one of them is revealed to be Albert Einstein?

[–] Im_old@lemmy.world 3 points 1 week ago

I'm not an expert but I'm sure somewhere it exists some anime of yuri AI robots. Rule34 demands it.

[–] General_Effort@lemmy.world 5 points 1 week ago (1 children)

What would you consider sufficient to confirm the story?

[–] L7HM77@sh.itjust.works 1 points 1 week ago (3 children)

Logs, breach method, a detailed step-through of specifically how and what happened, methods to guard against this in the future, anything really. We have bullshit machines now that can just make up something plausible in a few moments, but we still don't have any details.

Article mentions stolen credentials, and a "previously unknown exploit." What level were the credentials? Does the employee know how it was leaked? Where's the CVE?? Is this going to be patched, or is it a feature?

Without any more data, this is just Company A says "...", Company B says "...", and it smells like marketing.

[–] hard_zero1@discuss.tchncs.de 5 points 1 week ago (1 children)
[–] TheFogan@programming.dev 1 points 6 days ago* (last edited 6 days ago)

Doesn't really clear things up more, says "we detected an attack, we fixed the method it went in through, no further details needed".

So yeah basically it is open AI's claims to go further of "our models are so advanced that they can't be contained". It's a story that will bolster both of their investor value and send the message to governments and companies "the AI arms race is here, shots may be fired without even people attacking, and the only way to protect yourself is to have AI security guards".

It's literally 2 arms dealers telling us the war is already started. On the surface it sounds like it should be bad for them... but in reality it's just hype that benefits them in the long run, just like mass shootings do for gun manufacturers.

[–] partofthevoice@lemmy.zip 2 points 1 week ago* (last edited 1 week ago)

Yup.

The attack was initially surfaced through AI-assisted detection. Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise.

That’s in the article from HuggingFace. Not saying you’re right, but if you are, that’s what you were looking for.

https://huggingface.co/blog/security-incident-july-2026

[–] MrSulu@lemmy.ml 23 points 1 week ago

Dumb fucks.! How is not covered by the same principle as dog owners being accountable for their dogs actions?

[–] tangeli@piefed.social 17 points 1 week ago

When is Altman going to jail for hacking?

[–] GoatSynagogue@lemmy.world 16 points 1 week ago

I’m sure it did OpenAI lol.

[–] just_another_person@lemmy.world 16 points 1 week ago
[–] binux@sh.itjust.works 15 points 1 week ago

Of course! When you make your product do some stupid illegal shit, just blame the product as if it’s anything more than bloated autocorrect entirely without a will of its own. That definitely makes sense.

Watching these people crash and burn can’t come soon enough.

[–] Hupf@feddit.org 14 points 1 week ago

A computer can never be held accountable, therefore a computer must never hack into another company.

[–] green_goglin@thelemmy.club 11 points 1 week ago
[–] hot_mocha_decaf@lemmy.cafe 5 points 1 week ago (1 children)
[–] stoy@lemmy.zip 6 points 1 week ago (1 children)

I have no idea of the source for this image, but I like the aesthetic!

[–] eicker@lemmy.world 4 points 1 week ago

If AI can already chain together credential theft, vulnerability discovery, and exploitation with minimal human input, model capability is no longer the only race that matters. Security, containment, and responsible deployment need to advance just as quickly, or they’ll become the weakest link.

[–] hard_zero1@discuss.tchncs.de 1 points 1 week ago

This is obviously a big conspiracy where Huggingface claimed to have been hacked by an AI, 6 days before OpenAI attributes the attack to their model, so they can somehow profit, despite their alleged failures to secure their systems, from a stronger belief in the capabilities of AI. Surely, nobody but the Lemmy community would ever notice that LLMs are actually not capable of anything and everyone using them is just extremely stupid.