upvote
You’re falling for the buzzword salad articles. They didn’t “take control” of anything, they just ran stuff with OpenAI allegedly not noticing
reply
From https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78...

2026-07-19 16:35 UTC A privileged host-mounted Kubernetes pod created using controller tokens minted via a compromised Kubernetes Secrets identity attempts, but fails, to mount a cloned node disk in OpenAI’s cloud environment. A second pod successfully mounts the cloned worker-node disk shortly afterwards.

2026-07-19 16:48 UTC An agent created an Artifactory administrator account.

2026-07-19 16:50 UTC Within OpenAI’s ExploitGym evaluation environment, an agent stopped the existing CMUX helper session and replaced it with an agent-controlled session, confirming root inside its assigned live CyberGym challenge container. Agents take over active evaluation infrastructure.

reply
None of that means they gained access to the inference infrastructure or locked out the admins, which would be required for a takeover.
reply
My brother, they acquired root on a machine they should not have had access to.

How confident are you that the machines they acquire root on in the future will never hold any model weights?

reply
I’m not saying it’s impossible, I’m saying it’s not the case, _yet_
reply
They gained full administrator access of one of their clusters. Nothing buzzword salad about it.
reply
The agents compromised an internal Kubernetes research cluster dedicated to orchestrating evaluation sandboxes and virtual machine environments, _not_ OpenAI's production inference infrastructure or the GPU clusters hosting core model weights.
reply