12 hours ago · Tech · hide · 0 comments

Due to recent reports about “AI”/LLM/“agent” tools and services, I have growing concerns that the #security properties of the open web are changing, or have already changed, in practice, to a degree that we haven’t seen in many years.This past week’s articles / reports on further investigations and details of the OpenAI Hugging Face intrusion / incident: * OpenAI report: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf* 2026-08-26 https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/* 2026-08-28 https://www.planned-obsolescence.org/p/the-hugging-face-attack-surprisedand articles like:* 2026-08-26 https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/Previously I wrote about an instance of (presumably) unintentional subversion of site security by someone making mostly reasonable requests of a software “agent”:* 2026-08-24…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.