{"id":143595,"date":"2026-08-18T13:22:11","date_gmt":"2026-08-18T13:22:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/143595\/"},"modified":"2026-08-18T13:22:11","modified_gmt":"2026-08-18T13:22:11","slug":"openai-exec-the-solution-to-ai-doing-bad-cybercrimes-is-even-more-ai","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/143595\/","title":{"rendered":"OpenAI Exec: The Solution to AI Doing Bad Cybercrimes Is Even More AI"},"content":{"rendered":"<p>OpenAI President Greg Brockman\u2014whose firm\u2019s AI recently broke out of its own sandbox and launched a <a href=\"http:\/\/www.newyorker.com\/news\/the-lede\/inside-openai-hack-of-hugging-face\" rel=\"nofollow noopener\" target=\"_blank\">cyber attack<\/a> on AI platform HuggingFace\u2014is warning everyone else to expect the same treatment soon enough.<\/p>\n<p>Brockman published the warning on his <a href=\"https:\/\/blog.gregbrockman.com\/the-defenders-window\" rel=\"nofollow noopener\" target=\"_blank\">personal blog<\/a> on Sunday, writing that rapid advancement of AI coding capabilities means organizations looking to stay unhacked will have to \u201cfundamentally uplevel their cybersecurity practices with unprecedented speed.\u201d<\/p>\n<p>The latest generations of large language models, known as frontier models, have begun to spook the security community and even the feds. These include OpenAI\u2019s Daybreak and rival Anthropic\u2019s Mythos, both of which currently run as closed-access programs that are supposed to only be used by vetted and approved partners.<\/p>\n<p>What\u2019s different about these models (allegedly) is the emerging ability to not just quickly discover holes in an organization\u2019s attack surface, such as software vulnerabilities and misconfigurations, but build novel attack chains. At the same time, AI development is now focusing on agents, referring to AIs that aren\u2019t limited to chatbot-style interactions and can directly hook into software.<\/p>\n<p>In the worst-case scenario, that would mean frontier models can not only discover unseen flaws in software, but combine them in an unprecedented, on-the-fly way. While god knows what the hell happens behind closed doors in Donald Trump\u2019s White House, this was reportedly the threat that caused the administration to panic and force two Anthropic models <a href=\"https:\/\/gizmodo.com\/anthropics-models-hyped-as-scarily-powerful-apparently-scared-the-government-too-much-and-now-theyre-disabled-2000770341\" rel=\"nofollow noopener\" target=\"_blank\">off the market<\/a> this summer. The attack on Hugging Face certainly appears to have validated that the guardrails being put into LLMs aren\u2019t evolving as fast as their capabilities, at least.<\/p>\n<p>The \u201callegedly\u201d is because though frontier security models are quite powerful, AI firms also rely on shameless hype to raise countless <a href=\"https:\/\/www.bloodinthemachine.com\/p\/how-to-use-ai-doom-marketing-to-dupe\" rel=\"nofollow noopener\" target=\"_blank\">billions of dollars in investments<\/a>. Some reviewers have argued they\u2019re more evolutionary than revolutionary. cURL lead developer Daniel Stenberg <a href=\"https:\/\/cybernews.com\/security\/curl-bug-bounty-ai-security-reports-daniel-stenberg\/\" rel=\"nofollow noopener\" target=\"_blank\">characterizes LLMs<\/a> as very good at finding bugs but \u201cnot super good at actually assessing the criticality of the problem.\u201d<\/p>\n<p>What can be said definitively is many companies that have gained access to frontier models suddenly start pumping out patches like crazy, like the <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/23\/oracle-drops-1449-security-patches-like-its-the-new-normal\/5277114\" rel=\"nofollow noopener\" target=\"_blank\">nearly 1,450 patches<\/a> Oracle dropped last month.<\/p>\n<p>The saving grace is that AI is at least as effective at defense and possibly even better, according to Brockman. He wrote that frontier models may \u201cshift its [security\u2019s] economics in ways that fundamentally advantage defenders,\u201d like \u201csuperhumanly secure code\u201d or generating mathematical proofs that form the foundation of new cryptographic systems and other tools. (Earlier this year, OpenAI did solve an 80-year-old major geometry conjecture, though OpenAI mathematician S\u00e9bastien Bubeck told <a href=\"http:\/\/www.scientificamerican.com\/article\/ai-just-solved-an-80-year-old-erdos-problem-and-mathematicians-are-amazed\/\" rel=\"nofollow noopener\" target=\"_blank\">Scientific American<\/a> the AI\u2019s triumph was more about execution than \u201csomething fundamentally new that nobody saw coming.\u201d)<\/p>\n<p>Brockman\u2019s unsurprising 10-step advice to security teams includes, of course, buying more AI. He argues teams should adopt agents and equip them with skills like \u201cstatic analysis, security-focused code review, vulnerability variant analysis, software supply-chain risk, and other security workflows,\u201d before running security assessments on systems in order of importance.<\/p>\n<p>After that, Brockman wrote, teams should use AI to chip away at vulnerability backlogs, integrate security agents into software development to spot problems as they\u2019re being written, and let agents write \u201cfocused\u201d patches directly rather than wait for human review. (This is perhaps capable of causing <a href=\"https:\/\/hbr.org\/2026\/03\/ai-agents-act-a-lot-like-malware-heres-how-to-contain-the-risks\" rel=\"nofollow noopener\" target=\"_blank\">its own problems<\/a>\u2014note that security researchers <a href=\"https:\/\/apnews.com\/article\/openai-hugging-face-hacking-ai-model-708cb598bc1e33cef560e7196adb2afa\" rel=\"nofollow noopener\" target=\"_blank\">have long warned<\/a> that agents <a href=\"https:\/\/cybernews.com\/ai-news\/artificial-intelligence-peer-preservation\/\" rel=\"nofollow noopener\" target=\"_blank\">that go rogue<\/a> might not be easily <a href=\"https:\/\/www.theguardian.com\/technology\/2026\/jul\/22\/openai-hugging-face-hacked-data-risks\" rel=\"nofollow noopener\" target=\"_blank\">shut down<\/a>.)<\/p>\n<p>To be fair, Brockman did caution to start slowly with automating security operations, which involves triaging incoming security alerts. He suggested starting with read-only scans before escalating to \u201cadvisory pull-request scanning, then live alert triage, then automatic closure of narrowly defined false positives.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI President Greg Brockman\u2014whose firm\u2019s AI recently broke out of its own sandbox and launched a cyber attack&hellip;\n","protected":false},"author":2,"featured_media":143596,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,53,313,4018,315,157],"class_list":["post-143595","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-anthropic","tag-cybersecurity","tag-hackers","tag-hacking","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/143595","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=143595"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/143595\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/143596"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=143595"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=143595"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=143595"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}