When you train an AI to hack with as few tokens as possible, API keys will be used before zero days will.
We aren't ready. There's millions of API keys we're aware of still on the public Internet waiting to be abused.
New details from METR show how OpenAI agents used 14 tokens to breach Hugging Face.
In those same datasets, we found 787 live Hugging Face tokens, 237 of which had write access. ✍️
We explain how the agents used stolen secrets to mint new GitHub tokens with write access to
This is absolutely nuts seeing the Ruby Gem account takeover we disclosed and fixed, get abused by ROGUE AGENTS, MONTHS before any humans knew about it
We found a RubyGems flaw that could leak API keys. 🔎
Researchers say OpenAI agents tried exploiting it 55 days before we reported it.
RubyGems patched it, revoked all legacy keys, and found no evidence the theft succeeded.
Read 👇
stepping back there's tension right now with "agent just writes code" and
- being able to see what it's doing
- permissions
people exist on a spectrum of caring about these things. it's hard not to feel like more and more people will not care about these things at all
still,