Reproducing here an interesting comment I saw on Reddit:
OnlineParacosm • 23m ago
I’ve read security disclosures for 15 years and let me tell you guys I’ve never read anything quite like that blog post.
Based on this blog, it sounds like they intentionally turned off safety guardrails to test offensive capabilities. The deception here is burying the lede: they appear to have intentionally unleashed an unrestricted offensive cyber-agent, connected it to a system with a path to the internet, and it immediately attacked a major partner. The blog glosses over the gross negligence of giving an autonomous, unrestricted cyber-offense model a pathway to lateral movement.
There’s an entire cybersecurity specialization just for just vendor supply chain risk assessment, and their job is essentially to audit who you do business with as a company to determine if they are jokers. I would pay money to be a fly on the wall of one of those emergency meetings taking place right now after hours.
Any CISO in here looking forward to explaining this one tomorrow? Here I’ll open with the dumbest question you’ll get “ how can we protect ourselves [from out partner that we won’t fire]”



I dont think everyone realized how insane this situation is.
A state-level, lateral movement driven, platform compromise just got indirectly perpetrated by this company.
Any regular Joe would’ve been arrested and charged for such a situation (Im being polite with the word situation).
The stress, the utter confusion the staff at HF must have felt, not knowing who or what could be doing all these manoeuvers at the speed of light, is just a security nightmare becoming true.
What is the next step? Doing blog posts to raise their image and maybe get investments is downright wrong and disgusting.