I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://simonwillison.net/2026/Jul/22/ope…
Lesson: Independent writeups turn lab incidents into shared defender knowledge — don't dismiss as marketing.
I wrote about the completely wild incident where OpenAI were testing a new model and it broke out of its sandbox and broke INTO Hugging Face to steal the answers to the benchmark https://simonwillison.net/2026/Jul/22/openai-cyberattack/
Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick Frontier models can find and exploit vuln…
Lesson: Treat cyber-capable model incidents as real capability signals, not PR theater.
Tucked away in this article is an appeal to the AI skeptics to PLEASE stop writing off stories like this OpenAI accidental exploit of Hugging Face as a dishonest marketing trick
Frontier models can find and exploit vulnerabilities now, it helps nobody to pretend that they can't!
Midday is an all-in-one business assistant for freelancers that integrates time tracking, invoicing, and financial management. It features automatic invoice-to-transaction matching via Magic Inbox and a secure vault for …
Lesson: Open-source ops agents (invoice, vault, matching) are the freelancers' ERP.
Midday is an all-in-one business assistant for freelancers that integrates time tracking, invoicing, and financial management. It features automatic invoice-to-transaction matching via Magic Inbox and a secure vault for storing contracts.
https://github.com/midday-ai/midday
Safe adopt prompt · repo / library / tool
Copy into Claude / Grok / Codex / Cursor — investigates provenance & malware first, then plans LifeOS-compatible install only if safe.