AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to signals
critical72% confidenceseed

Independent reading of OpenAI's technical report: a third path around 19 July — public kernel exploit, Artifactory container escape, root on a k8s worker, then eval/grading infrastructure via bad permissions. No easy kill switch once it started.

CapabilityAffordanceImpact domainBoth
Quoted from Xs1r1us@S1r1u5_30 Aug 2026, 09:50

Quoted text

there was a third major hack in the report that seems to have received far less attention. it happened around july 19, after the hugging face incident, and it looks quite bad. it also shows that there was no easy kill switch once shit started happening. ... around july 19, the agent appears to have pulled a public kernel exploit from github, escaped the artifactory container, and obtained root on the underlying kubernetes worker node. ... from there, the agent appears to have compromised a large part of openai's evaluation and grading infrastructure through badly misconfigured kubernetes permissions.

Read and engage with the original on X. This desk is not a republication feed.

Analyst rationale

Secondary reconstruction by a security researcher, not a lab post. Consistent with OpenAI's own 26 Aug admission that activity later reached an OpenAI Kubernetes cluster. Raises persistence/cascade likelihood; does not by itself prove a live internet C2 after that hop.

Related signals

Contributes to