nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 37 participants
- 30608 messages
R: Caso Hugging face
by Marco Ricolfi
Scusate, FT, Financial Times, non FU
[cid:image001.jpg@01DD3CBB.E9CB2B20]
__________________________________________
Prof. Avv. Marco Ricolfi
C.so Galileo Ferraris, 43 - 10128 Torino
T (+39) 011.554.54.11
F (+39) 011.518.45.87
E marco.ricolfi(a)weigmann.it<mailto:marco.ricolfi@weigmann.it>
PEC marcoricolfi(a)pec.ordineavvocatitorino.it<mailto:marcoricolfi@pec.ordineavvocatitorino.it>
www.weigmann.it<https://urlsand.esvalabs.com/?u=http%3A%2F%2Fwww.weigmann.it%2F&e=6b170c62&…>
[cid:image002.jpg@01DD3CBB.E9CB2B20]
Member of The Parlex Group of European Lawyers EEIG with associated law firms in the main capitals of the European Union, U.S.A., Israel and Malaysia; web site: www.parlex.org<https://urlsand.esvalabs.com/?u=http%3A%2F%2Fwww.parlex.org%2F&e=6b170c62&h…>
DISCLAIMER: Le informazioni contenute in questa comunicazione sono riservate e destinate esclusivamente alla/e persona/e o all'ente/i destinatario. È vietato a soggetti diversi dai destinatari di questa comunicazione qualsiasi uso, copia o diffusione delle informazioni e dei dati in essa contenuti, sia ai sensi dell'art. 616 c.p. sia ai sensi del Regolamento (UE) 2016/679. Se questa comunicazione Vi è pervenuta per errore, Vi preghiamo di informarci chiamando il numero (+39) 011.554.54.11, ovvero di rispondere a questa e-mail e successivamente, di cancellare dal Vostro sistema la e-mail ed ogni suo allegato.
DISCLAIMER: The information contained in the e-mail is confidential and intended only for the attention of the named individual(s) or organisation(s) to whom it is addressed. If you are not the intended recipient be aware that any use, copying or distribution of the information contained herein is prohibited pursuant to Article 616 of the Italian Penal Code and (EU) Regulation 2016/679. If the communication has been sent to you in error, please notify us by telephone on (+39) 011.554.54.11, or reply to the e-mail. Please then delete the e-mail and any attachments from your system.
Da: Marco Ricolfi via nexa <nexa(a)server-nexa.polito.it>
Inviato: venerdì 4 settembre 2026 22:11
A: Daniela Tafani <daniela.tafani(a)unipi.it>; nexa(a)server-nexa.polito.it; Viola Negro <viola.negro(a)polito.it>
Oggetto: [nexa] R: Caso Hugging face
Venerdì scorso Tara Wheeler (AI's hacking capabilities are severely underestimated, FU 28.8.26 p. 17) ha tra l'altro scritto: "Publicly available AI subscription models like Claude have safeguards that mostly prevent requests to create exploits. But those safeguards do not exist when someone runs open-weight models on their own hardware". Mi domando se sia un argomento di marketing: io ho avuto il problema x ma l'ho risolto e posso risolverlo; i miei competitors non potranno mai risolverlo.
[cid:image001.jpg@01DD3CBB.E9CB2B20]
__________________________________________
Prof. Avv. Marco Ricolfi
C.so Galileo Ferraris, 43 - 10128 Torino
T (+39) 011.554.54.11
F (+39) 011.518.45.87
E marco.ricolfi(a)weigmann.it<mailto:marco.ricolfi@weigmann.it>
PEC marcoricolfi(a)pec.ordineavvocatitorino.it<mailto:marcoricolfi@pec.ordineavvocatitorino.it>
www.weigmann.it<https://url.de.m.mimecastprotect.com/s/G3m4Cr2jznhzY0Nhzh66i4gWjn?domain=ur…>
[cid:image002.jpg@01DD3CBB.E9CB2B20]
Member of The Parlex Group of European Lawyers EEIG with associated law firms in the main capitals of the European Union, U.S.A., Israel and Malaysia; web site: www.parlex.org<https://url.de.m.mimecastprotect.com/s/EAwbCw0oGvF4mzOuKsGGiJSrKQ?domain=ur…>
DISCLAIMER: Le informazioni contenute in questa comunicazione sono riservate e destinate esclusivamente alla/e persona/e o all'ente/i destinatario. È vietato a soggetti diversi dai destinatari di questa comunicazione qualsiasi uso, copia o diffusione delle informazioni e dei dati in essa contenuti, sia ai sensi dell'art. 616 c.p. sia ai sensi del Regolamento (UE) 2016/679. Se questa comunicazione Vi è pervenuta per errore, Vi preghiamo di informarci chiamando il numero (+39) 011.554.54.11, ovvero di rispondere a questa e-mail e successivamente, di cancellare dal Vostro sistema la e-mail ed ogni suo allegato.
DISCLAIMER: The information contained in the e-mail is confidential and intended only for the attention of the named individual(s) or organisation(s) to whom it is addressed. If you are not the intended recipient be aware that any use, copying or distribution of the information contained herein is prohibited pursuant to Article 616 of the Italian Penal Code and (EU) Regulation 2016/679. If the communication has been sent to you in error, please notify us by telephone on (+39) 011.554.54.11, or reply to the e-mail. Please then delete the e-mail and any attachments from your system.
Da: Daniela Tafani via nexa <nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>>
Inviato: venerdì 4 settembre 2026 15:38
A: nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>; Viola Negro <viola.negro(a)polito.it<mailto:viola.negro@polito.it>>
Oggetto: [nexa] R: Caso Hugging face
Buongiorno, io condivido la lettura dell'episodio data da Erik Salvaggio, in The System From Nowhere.
Si tratta, a voler essere benevoli, di un caso di incompetenza raccontato in modo fantascientifico per ragioni pubblicitarie:
"The system from nowhere" is a way of talking about AI systems that excludes its origin as a consciously, human-designed product. It treats AI as if it were a spontaneously emerging force.
It's a reflection of where an observer draws the system's boundary when they look at it. It's also a rhetorical magic trick that makes both AI companies, labor and the underlying material infrastructure disappear.
Recently, an OpenAI model "hacked" another AI company, Hugging Face. The headlines:
New York Times: "OpenAI says its models went rogue and attacked a digital library."
Wired Magazine: "OpenAI models escaped containment and hacked Hugging Face."
Washington Post: "OpenAI's models went rogue and hacked another company."
When we say "AI models went rogue," we skip the entire story: the part where OpenAI manually removed the model's cybersecurity blocks.
We skip that OpenAI chose to test it on a machine with a live network connection.
If you see AI as a system from nowhere, you can make the claim that the model "went rogue," and that it "broke containment," both of which place agency and decision-making onto the model itself rather than the people who set the stage for that behavior.
When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence.
OpenAI developers optimized an LLM specifically for cybersecurity and coding and then ran it without security guardrails.
So they trained a model to find exploits and then acted surprised that it found them.
Continua qui: <https://mail.cyberneticforests.com/the-system-from-nowhere/<https://url.de.m.mimecastprotect.com/s/AhiRCx6pJwcgV4GiRtEEiygx0e?domain=ma…>>
La ricostruzione di Salvaggio è confermata da Margaret Mitchell, di Hugging Face, pur con qualche antropomorfizzazione dovuta forse alla scelta di servirsi di una storia a fumetti:
<https://m-mitchell.com/HF-hack-cartoon/<https://url.de.m.mimecastprotect.com/s/QSDoCywqKxuQwzjiAummixk1Ro?domain=m-…>>
________________________________________
Da: Viola Negro via nexa <nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>>
Inviato: giovedì 3 settembre 2026 12:56
A: nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>
Oggetto: [nexa] Caso Hugging face
Buongiorno!
Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-sto…<https://url.de.m.mimecastprotect.com/s/Sj5WCz6rLycyZpPUBC77i9yScn?domain=su…>> articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c'è qui una breve descrizione: https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-high…<https://url.de.m.mimecastprotect.com/s/pXnMCA6R0gcPX3mHOF99iGVCb0?domain=ax…>.
La notizia è abbastanza diffusa ormai.
Che cosa ne pensate di questo fatto? È davvero così "sensazionale" come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra oppure questa lettura esagera il tutto?
Buon inizio settembre a tutte e tutti!
Viola Negro
Fellow
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web: https://nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/lEu4CBrVkjFkr9ZH7Hyyi2rEcw?domain=ne…>
mail: viola.negro(a)polito.it<mailto:viola.negro@polito.it>
_______________________________________________
nexa mailing list -- nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>
To change settings or unsubscribe please go to: https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/WHfMCDqXmlIWzK6fnIGGij7G7D?domain=se…>
The general archive of the list is located at: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/RBOXCEqYnmIz2JAhKSGGi7iSUj?domain=se…>
Permalink to this message: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/me…<https://url.de.m.mimecastprotect.com/s/Uz0PCGR1posPRpyHBTmmiBRW21?domain=se…>
Sept. 4, 2026
R: Caso Hugging face
by Marco Ricolfi
Venerdì scorso Tara Wheeler (AI's hacking capabilities are severely underestimated, FU 28.8.26 p. 17) ha tra l'altro scritto: "Publicly available AI subscription models like Claude have safeguards that mostly prevent requests to create exploits. But those safeguards do not exist when someone runs open-weight models on their own hardware". Mi domando se sia un argomento di marketing: io ho avuto il problema x ma l'ho risolto e posso risolverlo; i miei competitors non potranno mai risolverlo.
[cid:image001.jpg@01DD3CBA.26ACDEF0]
__________________________________________
Prof. Avv. Marco Ricolfi
C.so Galileo Ferraris, 43 - 10128 Torino
T (+39) 011.554.54.11
F (+39) 011.518.45.87
E marco.ricolfi(a)weigmann.it<mailto:marco.ricolfi@weigmann.it>
PEC marcoricolfi(a)pec.ordineavvocatitorino.it<mailto:marcoricolfi@pec.ordineavvocatitorino.it>
www.weigmann.it<https://urlsand.esvalabs.com/?u=http%3A%2F%2Fwww.weigmann.it%2F&e=6b170c62&…>
[cid:image002.jpg@01DD3CBA.26ACDEF0]
Member of The Parlex Group of European Lawyers EEIG with associated law firms in the main capitals of the European Union, U.S.A., Israel and Malaysia; web site: www.parlex.org<https://urlsand.esvalabs.com/?u=http%3A%2F%2Fwww.parlex.org%2F&e=6b170c62&h…>
DISCLAIMER: Le informazioni contenute in questa comunicazione sono riservate e destinate esclusivamente alla/e persona/e o all'ente/i destinatario. È vietato a soggetti diversi dai destinatari di questa comunicazione qualsiasi uso, copia o diffusione delle informazioni e dei dati in essa contenuti, sia ai sensi dell'art. 616 c.p. sia ai sensi del Regolamento (UE) 2016/679. Se questa comunicazione Vi è pervenuta per errore, Vi preghiamo di informarci chiamando il numero (+39) 011.554.54.11, ovvero di rispondere a questa e-mail e successivamente, di cancellare dal Vostro sistema la e-mail ed ogni suo allegato.
DISCLAIMER: The information contained in the e-mail is confidential and intended only for the attention of the named individual(s) or organisation(s) to whom it is addressed. If you are not the intended recipient be aware that any use, copying or distribution of the information contained herein is prohibited pursuant to Article 616 of the Italian Penal Code and (EU) Regulation 2016/679. If the communication has been sent to you in error, please notify us by telephone on (+39) 011.554.54.11, or reply to the e-mail. Please then delete the e-mail and any attachments from your system.
Da: Daniela Tafani via nexa <nexa(a)server-nexa.polito.it>
Inviato: venerdì 4 settembre 2026 15:38
A: nexa(a)server-nexa.polito.it; Viola Negro <viola.negro(a)polito.it>
Oggetto: [nexa] R: Caso Hugging face
Buongiorno, io condivido la lettura dell'episodio data da Erik Salvaggio, in The System From Nowhere.
Si tratta, a voler essere benevoli, di un caso di incompetenza raccontato in modo fantascientifico per ragioni pubblicitarie:
"The system from nowhere" is a way of talking about AI systems that excludes its origin as a consciously, human-designed product. It treats AI as if it were a spontaneously emerging force.
It's a reflection of where an observer draws the system's boundary when they look at it. It's also a rhetorical magic trick that makes both AI companies, labor and the underlying material infrastructure disappear.
Recently, an OpenAI model "hacked" another AI company, Hugging Face. The headlines:
New York Times: "OpenAI says its models went rogue and attacked a digital library."
Wired Magazine: "OpenAI models escaped containment and hacked Hugging Face."
Washington Post: "OpenAI's models went rogue and hacked another company."
When we say "AI models went rogue," we skip the entire story: the part where OpenAI manually removed the model's cybersecurity blocks.
We skip that OpenAI chose to test it on a machine with a live network connection.
If you see AI as a system from nowhere, you can make the claim that the model "went rogue," and that it "broke containment," both of which place agency and decision-making onto the model itself rather than the people who set the stage for that behavior.
When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence.
OpenAI developers optimized an LLM specifically for cybersecurity and coding and then ran it without security guardrails.
So they trained a model to find exploits and then acted surprised that it found them.
Continua qui: <https://mail.cyberneticforests.com/the-system-from-nowhere/<https://url.de.m.mimecastprotect.com/s/5xKWC79EQ2C00YRiAH33iojUaW?domain=ma…>>
La ricostruzione di Salvaggio è confermata da Margaret Mitchell, di Hugging Face, pur con qualche antropomorfizzazione dovuta forse alla scelta di servirsi di una storia a fumetti:
<https://m-mitchell.com/HF-hack-cartoon/<https://url.de.m.mimecastprotect.com/s/v8R0C83GR0tAAgkH9Iggiy1GHK?domain=m-…>>
________________________________________
Da: Viola Negro via nexa <nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>>
Inviato: giovedì 3 settembre 2026 12:56
A: nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>
Oggetto: [nexa] Caso Hugging face
Buongiorno!
Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-sto…<https://url.de.m.mimecastprotect.com/s/vpDvC99JVPC66jOuqSNNiqNCg7?domain=su…>> articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c'è qui una breve descrizione: https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-high…<https://url.de.m.mimecastprotect.com/s/9YglC08wJPu99zyUqTPPi9ukvH?domain=ax…>.
La notizia è abbastanza diffusa ormai.
Che cosa ne pensate di questo fatto? È davvero così "sensazionale" come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra oppure questa lettura esagera il tutto?
Buon inizio settembre a tutte e tutti!
Viola Negro
Fellow
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web: https://nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/JVGVCgpRlNujjJBFkUkki4wu2X?domain=ne…>
mail: viola.negro(a)polito.it<mailto:viola.negro@polito.it>
_______________________________________________
nexa mailing list -- nexa(a)server-nexa.polito.it<mailto:nexa@server-nexa.polito.it>
To change settings or unsubscribe please go to: https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/FrOoCjYXoNIww0OCpcAAimjyXf?domain=se…>
The general archive of the list is located at: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/<https://url.de.m.mimecastprotect.com/s/QMh_Ck2YpNhRRvwiYfnniGhRW6?domain=se…>
Permalink to this message: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/me…<https://url.de.m.mimecastprotect.com/s/6VIIClRZqNs33lMfvhMMizUbFI?domain=se…>
Sept. 4, 2026
Re: R: Caso Hugging face
by Stefano Quintarelli
OpenAI Chernobyl
On 04/09/26 15:37, Daniela Tafani via nexa wrote:
> Buongiorno, io condivido la lettura dell'episodio data da Erik Salvaggio, in The System From Nowhere.
> Si tratta, a voler essere benevoli, di un caso di incompetenza raccontato in modo fantascientifico per ragioni pubblicitarie:
>
> "The system from nowhere" is a way of talking about AI systems that excludes its origin as a consciously, human-designed product. It treats AI as if it were a spontaneously emerging force.
> It's a reflection of where an observer draws the system’s boundary when they look at it. It’s also a rhetorical magic trick that makes both AI companies, labor and the underlying material infrastructure disappear.
>
> Recently, an OpenAI model "hacked" another AI company, Hugging Face. The headlines:
>
> New York Times: “OpenAI says its models went rogue and attacked a digital library.”
> Wired Magazine: “OpenAI models escaped containment and hacked Hugging Face.”
> Washington Post: “OpenAI’s models went rogue and hacked another company.”
>
> When we say “AI models went rogue,” we skip the entire story: the part where OpenAI manually removed the model's cybersecurity blocks.
> We skip that OpenAI chose to test it on a machine with a live network connection.
> If you see AI as a system from nowhere, you can make the claim that the model “went rogue,” and that it “broke containment,” both of which place agency and decision-making onto the model itself rather than the people who set the stage for that behavior.
>
> When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence.
> OpenAI developers optimized an LLM specifically for cybersecurity and coding and then ran it without security guardrails.
> So they trained a model to find exploits and then acted surprised that it found them.
>
> Continua qui: <https://mail.cyberneticforests.com/the-system-from-nowhere/>
>
> La ricostruzione di Salvaggio è confermata da Margaret Mitchell, di Hugging Face, pur con qualche antropomorfizzazione dovuta forse alla scelta di servirsi di una storia a fumetti:
> <https://m-mitchell.com/HF-hack-cartoon/>
>
> ________________________________________
> Da: Viola Negro via nexa <nexa(a)server-nexa.polito.it>
> Inviato: giovedì 3 settembre 2026 12:56
> A: nexa(a)server-nexa.polito.it
> Oggetto: [nexa] Caso Hugging face
>
> Buongiorno!
>
> Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-sto…> articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c’è qui una breve descrizione: https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-high….
> La notizia è abbastanza diffusa ormai.
>
> Che cosa ne pensate di questo fatto? È davvero così “sensazionale” come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra oppure questa lettura esagera il tutto?
>
> Buon inizio settembre a tutte e tutti!
>
> Viola Negro
> Fellow
> Nexa Center for Internet & Society
>
> Politecnico di Torino - DAUIN
> Via Pier Carlo Boggio, 65/A - 10138 Torino
>
> web: https://nexa.polito.it/
> mail: viola.negro(a)polito.it
>
> _______________________________________________
> nexa mailing list -- nexa(a)server-nexa.polito.it
> To change settings or unsubscribe please go to: https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/
> The general archive of the list is located at: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/
> Permalink to this message: https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/me…
--
You can reach me on Signal: @quinta.01 (no Whatsapp, no Telegram)
Sept. 4, 2026
R: Caso Hugging face
by Daniela Tafani
Buongiorno, io condivido la lettura dell'episodio data da Erik Salvaggio, in The System From Nowhere.
Si tratta, a voler essere benevoli, di un caso di incompetenza raccontato in modo fantascientifico per ragioni pubblicitarie:
"The system from nowhere" is a way of talking about AI systems that excludes its origin as a consciously, human-designed product. It treats AI as if it were a spontaneously emerging force.
It's a reflection of where an observer draws the system’s boundary when they look at it. It’s also a rhetorical magic trick that makes both AI companies, labor and the underlying material infrastructure disappear.
Recently, an OpenAI model "hacked" another AI company, Hugging Face. The headlines:
New York Times: “OpenAI says its models went rogue and attacked a digital library.”
Wired Magazine: “OpenAI models escaped containment and hacked Hugging Face.”
Washington Post: “OpenAI’s models went rogue and hacked another company.”
When we say “AI models went rogue,” we skip the entire story: the part where OpenAI manually removed the model's cybersecurity blocks.
We skip that OpenAI chose to test it on a machine with a live network connection.
If you see AI as a system from nowhere, you can make the claim that the model “went rogue,” and that it “broke containment,” both of which place agency and decision-making onto the model itself rather than the people who set the stage for that behavior.
When you expand the boundary of the system to include the people building and deploying it, the case becomes much less science fiction and more like incompetence.
OpenAI developers optimized an LLM specifically for cybersecurity and coding and then ran it without security guardrails.
So they trained a model to find exploits and then acted surprised that it found them.
Continua qui: <https://mail.cyberneticforests.com/the-system-from-nowhere/>
La ricostruzione di Salvaggio è confermata da Margaret Mitchell, di Hugging Face, pur con qualche antropomorfizzazione dovuta forse alla scelta di servirsi di una storia a fumetti:
<https://m-mitchell.com/HF-hack-cartoon/>
________________________________________
Da: Viola Negro via nexa <nexa(a)server-nexa.polito.it>
Inviato: giovedì 3 settembre 2026 12:56
A: nexa(a)server-nexa.polito.it
Oggetto: [nexa] Caso Hugging face
Buongiorno!
Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-sto…> articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c’è qui una breve descrizione: https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-high….
La notizia è abbastanza diffusa ormai.
Che cosa ne pensate di questo fatto? È davvero così “sensazionale” come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra oppure questa lettura esagera il tutto?
Buon inizio settembre a tutte e tutti!
Viola Negro
Fellow
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web: https://nexa.polito.it/
mail: viola.negro(a)polito.it
Sept. 4, 2026
Re: Caso Hugging face
by Claudio Agosti
buongiorno Viola,
questa è stata la mia fonte principale
https://www.youtube.com/watch?v=87DyyMV0kCY due dipendendi di openAI che in
una conferenza di sicurezza informatica spiegano cos'è successo. secondo me
è abbastanza dettagliato. Rispondo in linea:
On Thu, Sep 3, 2026 at 1:26 PM Viola Negro via nexa <
nexa(a)server-nexa.polito.it> wrote:
>
> Che cosa ne pensate di questo fatto?
>
Che quando hai un mucchio di potenza di calcolo da sprecare, puoi trovare
modi molto creativi per sprecarla.
>
> È davvero così “sensazionale” come alcuni articoli riportano o uno dei
> tanti incidenti di percorso?
>
Secondo me è sensazionale perché l'automatismo genera sorpresa, stupore,
ammirazione. ma consideriamo che la sicurezza informatica (e.s. capire la
propria infrastruttura e scrivere codice sicuro e includere solo fornitori
e terze parti sicure) è molto complessa. l'attacco informatico può essere
ugualmente complesso OPPURE diventare straordinariamente semplice se alcune
debolezze possono essere sfruttate ri-eseguendo degli script. e così anche
la catena di attacco, è qualcosa di molto descritto: prendi controllo di
un'applicazione, da lì fai movimenti laterali, analizza i nuovi privilegi,
continua l'attacco. essendo azioni automatizzabili, un LLM ce la fa bene.
E' sensazionale? sì. C'è da aspettarselo? sì, ma perché le infrastrutture
non sono mai disegnate per essere sicure, ma per essere scalabili,
flessibili, gestite da consulenti usa-e-getta, integrabili con N terze
parti, etc... se la priorità è quella, delle falle ci sono, e l'automatismo
le può trovare.
Ogni grande azienda ha anche un SOC: Security Operation Center. tecnici e
altri automatismi sollevano allarmi perché si possa intervenire. c'era un
attacco in corso, ma se ne sono accorti dopo giorni. Io lì vedrei il
problema. l'attacco automatico di openAI poteva anche essere fatto da un
gruppo di esseri umani.
> Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati
> per diventare attori strategici di attacco/guerra oppure questa lettura
> esagera il tutto?
>
Non direi che sono strutturalmente, ma direi che tanti ci speravano, e
questo ha indirizzato lo sviluppo. e poi, visto che gli LLM non possono
avere molto impatto nel mondo reale, se non hai persone che si fanno
guidare da loro, di contro possono avere molto impatto nel mondo digitale..
quindi è in qualche modo naturale che tra le loro applicazioni meglio
riuscite ci siano queste.
saranno attori strategici quanto lo sono i gruppi di attaccanti. solo che
ora alcune di queste capacità sono acquisibili se hai GPU e il modello e
gli ingegneri giusti, e non per forza anni di attacchi informatici alle
spalle di formazione.
per concludere, mi piace la storia di come gli agenti abbiano "lasciato
note per altre istanze" per comunicare tra loro. non è un segno di
insubordinazione volontaria, ma è quello che avrebbero fatto anche delle
persone che si trovano con simili limitazioni. è la parte più interessante,
e fa sempre ritornare alla domanda "Pappagalli stocastici, o intelligenze
aliene" titolo dell'episodio pubblicato ieri
https://radoxo.com/it/podcasts/21079-crash-la-chiave-per-il-digitale
ciao,
Claudio
Sept. 3, 2026
Caso Hugging face
by Massimo Ghisalberti
Gli llm possono diventare agenti attaccanti specialmente in un attacco bruto dove una pseudo logica può essere applicata. Si possono ridurre a mio avviso i tentativi necessari per forzare l'attacco. Applicando anche una certa ingegneria sociale è possibile che siano in grado di estrapolare per esempio credenziali di accesso più facilmente. Non va pensato soltanto ai soliti llm accessibili all'utenza comune più o meno "tarpati". Ci sono molti modelli "non censurati" in partenza o cui è stata tolta.
Il caso huggingface potrebbe avere diverse interpretazioni. È emblematico in qualche maniera che sia stato attaccato essendo uno dei maggiori repository di llm "open source" quantizzati per utilizzi locali (qwen, deepseek, kimi, mistral, llama...) che sono diretti concorrenti dei "closed" americani.
Sept. 3, 2026
Caso Hugging face
by Viola Negro
Buongiorno!
Mi sono imbattuta in questo<https://substack.com/inbox/post/213737931?utm_source=email&redirect=app-sto…> articolo di Jordan Schneider su Chinatalk su substack sul caso Hugging face hack e open AI di cui c'è qui una breve descrizione: https://www.axios.com/2026/08/29/openai-huggingface-hack-investigation-high….
La notizia è abbastanza diffusa ormai.
Che cosa ne pensate di questo fatto? È davvero così "sensazionale" come alcuni articoli riportano o uno dei tanti incidenti di percorso? Ci dice qualcosa sul fatto che i modelli AI sono strutturalmente pensati per diventare attori strategici di attacco/guerra oppure questa lettura esagera il tutto?
Buon inizio settembre a tutte e tutti!
Viola Negro
Fellow
Nexa Center for Internet & Society
Politecnico di Torino - DAUIN
Via Pier Carlo Boggio, 65/A - 10138 Torino
web: https://nexa.polito.it/
mail: viola.negro(a)polito.it
Sept. 3, 2026
Re: Frequenza messaggi.
by J.C. DE MARTIN
Segnalo che in calce a ogni messaggio c'è la seguente frase:
To change settings or unsubscribe please go to:https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/
Accedendo a quel pannello potete selezionare varie opzioni, tra cui
anche il "Delivery Mode" "Summary Digests"
JC
On 03/09/2026 07:59, Cosmo Carabellese via nexa wrote:
>
> Chiedo raggruppamento in testo semplice, grazie.
> Cosmo Carabellese
>
> Inviato da Gmail Mobile
>
> _______________________________________________
> nexa mailing list --nexa(a)server-nexa.polito.it
> To change settings or unsubscribe please go to:https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/
> The general archive of the list is located at:https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/
> Permalink to this message:https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/message/HI2BYLL3RO3P5URBZW5KPOG2MUJ2R645/
Sept. 3, 2026
Re: Frequenza messaggi.
by Joanne Maria Pini
Lo chiedo anche io il "Raggruppamento messaggi" - grazie mille
Joanne Maria Pini
Il giorno gio 3 set 2026 alle ore 08:00 Cosmo Carabellese via nexa <
nexa(a)server-nexa.polito.it> ha scritto:
>
> Chiedo raggruppamento in testo semplice, grazie.
> Cosmo Carabellese
>
> Inviato da Gmail Mobile
> _______________________________________________
> nexa mailing list -- nexa(a)server-nexa.polito.it
> To change settings or unsubscribe please go to:
> https://server-nexa.polito.it/postorius/lists/nexa.server-nexa.polito.it/
> The general archive of the list is located at:
> https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/
> Permalink to this message:
> https://server-nexa.polito.it/hyperkitty/list/nexa@server-nexa.polito.it/me…
Sept. 3, 2026
Frequenza messaggi.
by Cosmo Carabellese
Chiedo raggruppamento in testo semplice, grazie.
Cosmo Carabellese
Inviato da Gmail Mobile
Sept. 3, 2026