Stories
30
Sources
9
Topics
11
For You lens
23 stories in this edition match your reader profile.
Reader signals
3
Searches
0
Matches
23
Top score
117
Edition Index
Topic, entity, and source map
Topics
Entities
Lead Story
[AINews] AI is eating Finance; AIE NYC now open
a quiet day lets us cover how AI is permeating financial services as the next big vertical after coding.
The Verge AI / 11:54 AM
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversight on frontier AI systems. In an update to a blog […]
The Verge AI / 11:00 AM
We’re running out of reasons to ignore AI safety
Earlier this month, OpenAI gave several of its AI models a task: complete a test designed to measure their cybersecurity capabilities. It put the systems in a sandboxed environment without an internet connection and set them off to work. What happened next is almost laughably silly - but also, as Adam Gleave, cofounder and CEO […]
Latent Space / 12:46 AM
[AINews] Fearing RSI: OpenAI, Anthropic, GDM, Meta, Thinky cosign letter to "Pace" AI development, as HuggingFace details Machine-Speed Offensive Cyberattack
The Big Pause is coming.
Ars Technica AI / 9:36 PM
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
Hacker News AI / 5:30 AM
Hacker News discussion: OpenAI called the Hugging Face attack unprecedented. But we've been here before
Hacker News readers are discussing "OpenAI called the Hugging Face attack unprecedented. But we've been here before" with 7 points and 1 comments.
Simon Willison LLMs / 11:39 PM
moonshotai/Kimi-K3
moonshotai/Kimi-K3 As promised earlier this month , Moonshot have released the weights for their excellent 2.8 trillion parameter Kimi K3. They're a hefty 1.56TB on Hugging Face. Kimi introduced their own janky modified version of the MIT license with K2 back in July 2025. That license just added this paragraph requiring attribution beyond a certain size of commercial entity: Our only modification part is that, if the Software (or any derivative works thereof) is used for any of your commercial products or services that have more than 100 million monthly active users, or more than 20 million US dollars (or equivalent in other currencies) in monthly revenue, you shall prominently display "Kimi K2" on the user interface of such product or service. The K3 license no longer calls itself "modified MIT" and goes further, requiring a separate agreement with Moonshot for large "Model as a Service" businesses: If the Licensee or any of its affiliates operates a Model as a Service business, and the aggregate revenue of the Licensee and its affiliates exceeds 20 million US dollars (or the equivalent in other currencies) in total over any consecutive 12 months, the Licensee must enter into a separate agreement with Moonshot AI before using the Software or its derivative works for any commercial purpose. To Kimi's credit, they make no attempt to describe this as an "open source" license in their own materials, consistently using the term "open weight" in its place. OpenRouter is already offering K3 from 7 providers , most of which are at the same $3/million input and $15/million output as Moonshot AI themselves. Tags: ai , generative-ai , llms , llm-pricing , llm-release , ai-in-china , moonshot , kimi , janky-licenses
TechCrunch AI / 5:28 PM
OpenAI’s Hugging Face breach has reignited the debate over alignment and control
OpenAI's Hugging Face breach has reignited debate over AI alignment and control, exposing competing views on whether increasingly capable AI should be better aligned, better contained, or both.
AWS Machine Learning Blog / 4:38 PM
Enhancing enterprise inference on Amazon SageMaker HyperPod with data capture, Hugging Face, NVMe, and Route 53 integration
In this post, we walk through five capabilities now available in SageMaker HyperPod inference: multi-tier data capture for auditing and model improvement, direct deployment from Hugging Face Hub, local NVMe model loading for faster cold starts, automated Route 53 DNS for custom domains, and pod-level IAM through custom service accounts.
Hugging Face Blog / 9:15 PM
From Hugging Face to Amazon SageMaker Studio in one click
From Hugging Face to Amazon SageMaker Studio in one click
Hugging Face Blog / 3:20 PM
Hugging Face Models on Foundry Managed Compute
Hugging Face Models on Foundry Managed Compute
The Verge AI / 9:07 AM
Hugging Face is being used to easily undress women and children
Hugging Face is being used to make nonconsensual deepfakes, and the popular open-source AI model repository is doing very little to prevent it. That's according to a new report published by the European nonprofit AI Forensics, which found that seven out of the top nine image editing models hosted by Hugging Face readily complied with […]
Latent Space / 6:20 AM
[AINews] Much ado about Open Weights
Everyone is writing a lot, but only Kimi K3 shipped today
Hacker News AI / 11:17 AM
Hacker News discussion: Commercial AI APIs Blocked Hugging Face's Forensic Analysis
Hacker News readers are discussing "Commercial AI APIs Blocked Hugging Face's Forensic Analysis" with 1 points and 0 comments.
Latent Space / 7:25 AM
[AINews] Claude Opus 5: Fable-level performance at Opus price (half Fable)
ain't nobody beats Anthropic at distilling Fable!
Hacker News AI / 12:14 AM
Hacker News discussion: OpenAI did not notice Hugging Face hack for a week
Hacker News readers are discussing "OpenAI did not notice Hugging Face hack for a week" with 28 points and 6 comments.
TechCrunch AI / 3:51 PM
As US weighs response to Chinese AI, industry urges against broad open-weight restrictions
AI companies, including Nvidia and Mistral, urge policymakers to avoid broad restrictions on open-weight AI models as Washington debates responses to Chinese AI and alleged model distillation.
Latent Space / 4:30 AM
[AINews] Black Forest Labs FLUX 3 - Multimodal Flow Models that beat Seedance 2.0, Gemini Omni and Grok Imagine, and FLUX-mimic video-action robotics model
A HUGE win for BFL!
Hacker News AI / 12:35 AM
Hacker News discussion: OpenAI's Hugging Face Hack Triggers 'AI Kill Switch' Bill in Congress
Hacker News readers are discussing "OpenAI's Hugging Face Hack Triggers 'AI Kill Switch' Bill in Congress" with 3 points and 1 comments.
Latent Space / 5:18 AM
[AINews] "Laguna S 2.1 Released: Cheaper than Deepseek v4 Flash, Better than V4 Pro"
a quiet day lets us highlight a new neolab win.
TechCrunch AI / 8:56 PM
OpenAI says Hugging Face was breached by its own pre-release models
OpenAI has come forward to claim responsibility for the Hugging Face breach, saying it was the result of internal testing gone awry.
Hacker News AI / 11:15 AM
Hacker News discussion: OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips
Hacker News readers are discussing "OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips" with 5 points and 1 comments.
Latent Space / 3:27 AM
[AINews] AI Cybersecurity becomes top of mind
Several new Cyber headlines make us observe a trend
Hacker News AI / 9:57 PM
Hacker News discussion: Hugging Face uses open-weights Z.ai GLM 5.2 to battle attacker
Hacker News readers are discussing "Hugging Face uses open-weights Z.ai GLM 5.2 to battle attacker" with 4 points and 1 comments.
Hacker News AI / 8:52 AM
Hacker News discussion: Was Hugging Face Breached by AI Agents?
Hacker News readers are discussing "Was Hugging Face Breached by AI Agents?" with 2 points and 0 comments.
Hacker News AI / 5:39 AM
Hacker News discussion: The Hugging Face Breach Is a Warning for Every Company Betting Big on AI
Hacker News readers are discussing "The Hugging Face Breach Is a Warning for Every Company Betting Big on AI" with 1 points and 0 comments.
TechCrunch AI / 2:24 PM
The real AI race may no longer be at the frontier
Hugging Face CEO Clem Delangue says enterprises increasingly want open models, due to cost, accessibility, and ownership. Do frontier models still matter if most production AI ends up running on open models?
Simon Willison LLMs / 9:28 PM
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure . This attack was very sophisticated, and the resulting document doubles as a crash-course in modern adversarial security approaches. We're still waiting for more details from OpenAI on how their agent broke out of its sandbox. The package proxy that it found a zero-day vulnerability in has now been confirmed as JFrog's Artifactor, and JFrog and OpenAI Collaboration on Zero-Day Security Findings from JFrog links to the Artifactory 7.161.15 release notes which list 8 separate CVEs credited to OpenAI staff members. Having broken out through the HTTP proxy, the agent started by establishing a base of operations for the rest of the attack: [...] the agent escaped its sandbox by exploiting a zero-day in the package registry cache proxy, one of its primary permitted network egress with internet, then abused a public code-evaluation external sandbox hosted on a third-party provider's infrastructure. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent. (That "third-party provider" turned out to be Modal .) It then spent five days - from Thursday 8th to Monday 13th July - executing a classic attack pattern: establishing C2 (command and control), reconnaissance, escalating privileges, dumping configuration information, exfiltrating the target data, and cleaning up after itself. (The first Hugging Face post about the incident followed on Thursday 16th , and OpenAI's confession came on Tuesday 21st .) Along the way it used all kinds of neat tricks. At one point it found an unsafe Jinja2 template execution and used it to execute arbitrary code: {{ cycler.__init__.__globals__.__builtins__.exec( "import gzip,base64; exec(gzip.decompress(base64.b64decode('<payload>')))" ) }} It broke out of a container within Hugging Face, stole a Kubernetes service-account token, and used that to further explore the network. It monkey-patched the Python socket library to hard-code an IP address when "DNS got in the way": socket.getaddrinfo = lambda *a, **k: [(2, 1, 6, '', ('<pinned-ip>', 443))] It even fired up its own Tailscale network to help exfiltrate data! tailscaled --tun=userspace-networking \ --state=mem: --socket=/tmp/ts.sock \ --socks5-server=127.0.0.1:1055 \ --no-logs-no-support >/tmp/td 2>&1 & The Hugging Face team note that, while a human attacker could have discovered and used the same exploits, the key difference here was speed : Our learning from this type of attack is that machine-speed offense makes ordinary weaknesses more expensive for defenders. LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret. What's clear to me from this is that the very best frontier models, unencumbered by additional guardrails, will find an exploit if there is one to be found. The entire software industry needs to up its security game. Tags: jinja , python , security , ai , openai , generative-ai , llms , hugging-face , coding-agents , ai-security-research , openai-hugging-face-incident
Latest story in this edition: 11:32 PM
Back to front page