@jcoglan Kind of. It wasn't totally isolated from the Internet but had a "a curated allowlist that permits routine package installation". The AI got past the allowlist, and then successfully attacked an external company. It's still potentially worrying, even if only because more people are likely to be running poorly-isolated hacking AIs. https://simonwillison.net/2026/Jul/22/openai-cyberattack/
theoesc@mastodon.social
@theoesc@mastodon.social