The passage describes a security incident involving OpenAI, Hugging Face, and JFrog, and argues that AI models are becoming powerful tools for discovering and chaining vulnerabilities at machine speed
Models Don't Go Rogue
news
mail.cyberneticforests.com
IrregularChat: AI & Autonomy
Sep 3
The essay explains the OpenAI/Hugging Face hacking incident and argues it was not evidence of a “rogue AI.” OpenAI and METR reported that the event came from cybersecurity testing using ExploitGym, a
socket.dev
news
socket.dev
IrregularChat: Purple Team
Jun 10
Socket’s threat research team uncovered a new PyPI wave tied to the broader Mini Shai-Hulud, Miasma, and Hades supply chain campaign. The latest wave adds 23 newly identified package-version artifacts
Bitwarden CLI was compromised in a supply chain attack tied to the ongoing Checkmarx campaign, according to JFrog and Socket. The affected release was **@bitwarden/cli@2026.4.0**, which contained mali