Comment by Animats

6 days ago

Does "To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy" just mean somebody had an open redirect? Those are still common.[1]

[1] https://sitetruth.com/reports/phishes.html

I expect it must have been more than just an open redirect if it let the models then go on to execute a bunch of vulnerabilities against Hugging Face.

> the models identified and exploited a zero-day vulnerability

This use of language is very hard to reconcile with the "AI is just a tool" rhetoric that many use.

Did the models do this, or did humans at OpenAI do this using the models?