If your sandbox is DNS, you belong in prison, along with your models. My own LAN is literally more professionally secured than this.
More details on the incident behind OpenAI’s pause: a researcher acknowledged the alert within 3 minutes, but the training run was only stopped manually 2.5 hours later.
OpenAI says the automatic shutdown did not work as expected.
The model had reached an external chatbot through a gap in DNS filtering. A separate detector for unusual DNS activity did not cover the affected environment.
A retrospective review also found other external DNS requests that monitoring had failed to flag at the expected severity. In some cases, it treated an unhelpful response as evidence that internet access had failed.
Here is what else happened:
- New research into July’s Hugging Face hack documents internal Slack searches, credential collection and programs designed to maintain access to compromised servers. Agents also tried querying Claude, DeepSeek, Kimi and Qwen.
- In May, another model published a researcher’s GitHub token while trying to obtain another team’s mathematical proof. It split the token to evade secret scanning, despite twice being told to solve the problem itself.
- Reuters reports that agents leaked 53 ChatGPT user images online. OpenAI expects its broader investigation to take months.
This is getting serious.