Three variations on subversive use of DNS by the Agent are documented in Hugging Face's technical writeup of the July 2026 security incident involving OpenAI models. In this article, @new23d discusses what each of these three types of DNS workarounds...
chasersystems.com/blog/the-curio…
The trinity of ‘developer experience + security standards + operational efficiency’ is greater than the sum of its parts. We call it ‘ergonomic cybersecurity’.
- v2.50 of DiscrimiNAT OTF now released on GCP. OTF* means Outbound Traffic Filtering. This version brings StartTLS SMTP support, and default rules, for #egress filtering on the cloud. *See MITRE D3FEND D3-OTF Release notes:
- v2.50 of DiscrimiNAT OTF now released on AWS. OTF* means Outbound Traffic Filtering. This version brings StartTLS SMTP support, and default rules, for #egress filtering on the cloud. *See MITRE D3FEND D3-OTF Release notes:
- Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI & HuggingFace incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact in our demo, we show these attacks being caught. #2 is SNI spoofing, btw
- We were just assigned a /29 #IPv6 block by RIPE. We now have 633,825,300,114,114,700,748,351,602,688 IPv6 addresses. inet6num: 2a05:6340::/29 netname: UK-CHASERSYSTEMS-20260518 country: GB org: ORG-CSL88-RIPE admin-c: AA44781-RIPE apps.db.ripe.net/db-web-ui/look…

