Comments
Clive Robinson • October 2, 2026 6:48 PM
@ Bruce, ALL,
Have you considered just how truthful or not OpenAI was?
Over Not just the big news but thousands perhaps millions of other attacks their “AI testing” made?
It would appear it’s a very untruthful series of responses at best… And is having knock on effects
BREAKING: OpenAI’s security fiasco explodes — and could tank Jensen Huang’s reputation
More and more facts are coming out and they are absolutely damning
“OpenAI’s software didn’t just attack Hugging Face.
It didn’t just attack a German web server.
It didn’t just attack Australia’s government servers.
And Australia apparently wasn’t the only country attacked by OpenAI’s software.
Worse, in disclosing what happened, OpenAI has dragged their feet every along the way.
§
About the closest thing to an honest account of what happened – and I seriously doubt even this is completely candid – came out about an hour ago. Even this was still a mix of euphemism (“attacks” were called “interactions”) and partial disclosure.“
https://garymarcus.substack.com/p/breaking-openais-security-fiasco
It was posted in the evening of 25th Sept.
The reason I did not post it earlier is I was waiting to see what the response from OpenAI was going to be…
Also other actors in the drama…
I suggest people read it rather than me go through why Altman and Trump should be put on the block.
Joseph Kanowitz • October 2, 2026 11:52 PM
ב”ה,
This thing with certain providers throttling certain customers’ data service to prevent patches while “Super Intelligence” is mostly unleashed against the US economy “because that’s where it escaped Jurassic Park” is going to be lit.
StephenM • October 3, 2026 2:43 AM
@Clive
Not a good idea to attack Medicare, Australia’s universal health care provider. Their servers will contain private and confidential information on just about every Australian. The medicare system is now decades old. It is not great but there is widespread public support. So this is not just an attack by a foreign company on the government but on every Australian and on democracy.
And no, the data wasn’t just public. Another ABC report https://www.abc.net.au/news/2026-10-02/rogue-open-ai-agent-breach-nsw-government-website/107223108 says:
“The agent gained access to both public and non-public data, but no personal Medicare details were breached.”
“OpenAI said the incident occurred during a training exercise of an ‘internal-only OpenAI model’, with the bot gaining access to non-public access to Services Australia Medicare’s Statistics Reporting Service.”
Every Australian is owed a detailed explanation by OpenAI of just what it was up to.
Clive Robinson • October 3, 2026 5:10 AM
@ StephenM,
You note,
“Every Australian is owed a detailed explanation by OpenAI of just what it was up to.”
Way more than an explanation, and way more than a grovelling apology. And verifiable remedial action[1].
One of the things that really annoyed me was the UK deal with Palantir.
Let’s be honest Peter Thiel is not normal, and Palantir reflects some of the worst of his aberrations.
The UK Government without permission or authority from the patients in the “National Health Service”(NHS) records system just gave the lot to Palantir to crunch up in their ML systems.
What the deal actually was all about, I have not found out. What I do know is that the chance of it being beneficial to me or any other NHS patients is very probably less than zero, otherwise politicians would be crowing about it…
Thus as Sam Altman is as bad if not actually worse, I do not expect anything of worth coming out from OpenAI… So far as an expectation it does not appear to be wrong.
[1] I know there are going to be a bunch of people doing a “what’s the harm”… Well to them I suggest they study history from nearly a century ago and what happened to people who had adverse medical records in not just Europe but The US with regards eugenics.
Ismar • October 3, 2026 6:32 AM
@ StephenM AI is just one part of the problem, the other is, off course, the current state of government cybersecurity allowing these attacks to be successful
Clive Robinson • October 3, 2026 3:53 PM
@ lurker, ALL,
With regards,
“[B]ut if there was any harm how come the owners/operators of all these “violated” websites didn’t see anything amiss?”
The old question of “harm to hurt” arises…
If I stick a pin in you, you generally go “ouch” fairly quickly. But there are diseases on the rise where you can be unaware of the pin. (Such as neuropathy from Type II Diabetes[1]).
Due to a US Doctor who developed K-Rations, “sugar in everything with no fat” was pushed as “heart healthy”. Scientists knew this back in the 1970’s but the food industry played dirty tricks which we still see with “Low Fat” and similar labels.
Then there are lifestyle issues inflicted by “professional others”. Few remember that Doctors used to tell patients to smoke tobacco and drink alcohol… Even long after they knew it was not a good idea (oh and cigarette manufactures were putting asbestos in the “filter tips”). Only now are the Drs saying neither is good and that there really is no “safe lower limit”. Yet the science community were saying half a century ago. As for asbestos even though it’s extremely dangerous in some parts of the world it’s still used like we do “plaster board”…
They all have something in common,
“The harm is done long before the hurt”.
Lets be honest cancer is not a nice way to go, nor are the various forms of heart failure, but in general by the time you know you’ve got them, it’s very long after the causal events.
Similar applies to websites, the actual harm comes in three steps,
1, Defective software/hardware built.
2, Defects then get turned into exploitable vulnerabilities.
3, Only some times do the exploits get noticed.
It’s the third point where APT used to be talked about, where “silent attackers” built themselves in in ways that were not seen and could not be removed.
To be noticed “attackers” have to “make noise” etc. The smart ones don’t make noise untill they have to.
It’s why I talk about “Segregation / Gapping” as often as I do and that it should be the foundation of a solid security plan, because,
“If an attacker can not reach the system they can not attack it”.
But also,
“It shows up abnormal activity more easily, thus increases the chance of spotting even stealthy attackers”.
Because for something to be spotted the signal it creates has to be visible above the general noise level in some way.
[1] There are three arguments that have been used in the past for the rise of Type II Diabetes…
1.1, Eating to much
1.2, Lack of exercise
1.3, Eating overly processed foods.
But modern science research has shown that the real culprit is the third one, and it’s a deliberate policy of not just the food industry but many governments.
But what you don’t hear about is that it can be due to the fact you have another disease or medications that effects the essential micro nutrants etc you body gets out of food. So your body reacts like it does when you’ve had to little water or food, it makes you crave them.
StephenM • October 3, 2026 6:10 PM
@Clive
“One of the things that really annoyed me was the UK deal with Palantir.”
There must be rules restricting access to medical data particularly for non medical reasons. It seems a little surprising that giving the data to Palantir wasn’t against those rules.
I wonder in what jurisdiction the data is held and what the laws are in that jurisdiction governing access to it.
Clive Robinson • October 3, 2026 9:59 PM
@ StephenM, ALL,
Whilst the sentiment against Palantir has been growing over the fact that Patients Private Data has been leaked not just to other non NHS subcontractors, but similar in other UK Government organisations and their subcontractors and outwards into foreign “Data Brokers”
Which is a direct breach of UK legislation. Some have noted that the change to US Legislation that makes all data held by US companies no mater where available to the US Gov puts all UK Patient data at risk.
But the latest anti Palantir voices are due to the death and harms caused by Palantir involvement in Gaza and ICE targeting individuals.
But another aspect is that of “Sovereign Data Processing” which is near nonexistent. Currently due to US legislation and US Technology Companies “Cloud Systems” very little “Data Privacy” or confidentiality actually now exists in the UK, Europe, and many other parts of the world.
For instance, for some time now the Systems used by UK MPs and even security services are on Microsoft and other US Tech suppliers servers out of Southern Ireland…
Not All Is Lost • October 3, 2026 10:35 PM
Yo Daisy,
you can stop by on Monday or Tuesday for an appointment and some training in OpSec and maybe some Situational Awareness. I will be available between 10AM and Noon for you on Oct 5 and 6 2026. I suggest you take advantage of this unique and rare opportunity. Have a pleasant Sunday.
lurker • October 3, 2026 10:39 PM
Latest on FlyDubai FZ1073 says the weapon was the aircraft’s own “crash axe”, a small hand axe kept in the cockpit for gaining access/egress when doors are jammed after a crash. In the light aircraft I trained in it was kept under the lefthand seat (pilot in command) and secured by ring-pull pins. It must be somewhere more accessible in a B 737 max8.
Clive Robinson • October 4, 2026 6:49 AM
@ Bruce, ALL,
AI luminary Le Cun is not fazzed by Existential AI claims.
There are an increasing number of people that are realising that the bottom line to Existential AI can only happen through unrestrained physical agency either directly or indirectly, with that only being possible through “Human failings”.
That is the reality is,
“It will be humans doing it to humans”
With the AI being little more than a “tool in the chain”.
So from a view point that basically says Anthropics Amodi is either deluded or a Charlton or part of the EA Cult pervading the US over payed AI clique
We have the following article,
AI ‘godfather’ Yann LeCun has ‘zero concerns’ about human extinction, says Anthropic CEO Dario Amodei is ‘deluded’
Yann LeCun won the 2018 Turing Award—computer science’s equivalent of the Nobel Prize—along with fellow AI researchers Geoffrey Hinton and Yoshua Bengio for their work on deep learning, the neural network technology that underpins today’s AI boom. But today, nearly a decade later, LeCun is the only one of the three AI “godfathers” who is not deeply concerned about the risks of artificial intelligence. In fact, he thinks many of those risks are overblown, and that the constant warning about them from executives at some of the leading AI companies is misguided and counterproductive.
“LeCun isn’t worried “at all” about AI wiping out humanity, and he has “zero concerns” about the recent string of rogue AI incidents, including OpenAI’s agents autonomously hacking Hugging Face in July. He attributes the incidents to poor human oversight and system design, and says they’re “totally preventable,” a belief also held by U.S. Treasury Secretary Scott Bessent, who this month called the Hugging Face incident the “responsibility of OpenAI management.”
“Those agents are doing exactly what they’ve been asked to do,” LeCun said. “They were supposed to be in sandboxes, but the sandboxes were leaky and horribly designed.” Many AI labs lack a fundamental understanding of cybersecurity, he said, something an OpenAI safety researcher also called out this week as one of the main reasons AI may cause “great harm to the world.”“
Where he and I differ is I now know that neither “Guard-rails or sandboxes” can be made sufficiently secure in use.
Thus people will be able to prompt inject or similar through the Guard-Rails. And AI will be able to do the reverse to escape the Sandboxes.
(Yes there is proof of this but surprisingly next to nobody wants to acknowledge it).
Thus the only secure way to run these Frontier AI systems is if they are “physically segregated” in some manner, and then only if humans do not do dumb things to “gap cross”.
Anonymous • October 4, 2026 8:04 PM
@Clive Robinson,
just write a d@mn3d book already, jesus christ, if ya think I’m gonna read your “stories” in the comment section of a blog – you’re plainly d31u$10n@1 bruh….
You’re a true $ykk0…. get a hobby, a woman, g3t 1@1d, watch a movie, documentary, find a friend (if ya can, I would never b your friend, but there’s always those f001$ out there who’d worship you and the like).
Are you even aware of your c0nd1t10n man? You p00p around like a bird and don’t even care about it. You’re so 0bn0x10us, WTF are you trying to prove????
ResearcherZero • October 5, 2026 4:18 AM
@Clive Robinson
AI integration into systems for use to ingest and analyze data, such as the Pentagon rollout of AI.mil, breaks segmentation and grants wide access to datasets. Once basic security measures are weakened, it is only a matter of time until daily use and mistakes in procedure allow incidents to take place. Most military personnel are not security aware.
Even in secure facilities that have multiple procedures in place to prevent lapses of security, and with staff trained in correct procedure and protocols, mistakes happen.
A researcher at a Siberian institute that works to prevent the spread of infectious disease and bacteria in northern Russia, has become infected with an unknown strain of pneumonic plague. 200 people have been placed under observation and hospitals closed in the region.
Russian authorities are confident the situation is under control and contained.
https://edition.cnn.com/2026/10/04/europe/russia-laboratory-plague-accident-intl
Subscribe to comments on this entry
Sidebar photo of Bruce Schneier by Joe MacInnis.









English (US) ·