Inside OpenAI's Black Hat Confession
August 8th, 2026
2 hrs 14 mins 10 secs
Tags
About this Episode
(Presented by TLPBLACK: A cybersecurity intelligence platform focused on sharing curated, high-sensitivity threat insights and research with trusted security professionals.)
Three Buddy Problem - Episode 108: OpenAI got on the Black Hat stage and walked through how its own agent swarm hacked Hugging Face. We discuss and struggle to decide whether to clap or panic.
Plus, why only the attacker can do forensics now, frontier models being built as cyber-weapons on purpose, APT29's "Dark Hotel" comeback in luxury hotels, China's swipe at Palo Alto, the Iran-water-system FUD, and an eye-opening Liechtenstein money-laundering hack.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Timestamps:
0:00 Introductory banter - Black Hat went full RSA
1:11 TLP Black sponsor read
3:58 A deflated, AI-pilled show floor
8:31 AI stunt hacking and AI slop
16:20 The OpenAI–Hugging Face talk
21:00 Not all the same incident: OpenAI vs. Meta, Anthropic, and Irregular
25:49 Swarms of agents, Artifactory message boards, and the defense gap
32:26 Offense vs. defense: what's really in the training data?
41:22 Guardrails, KYC, and "too dangerous to release"
48:07 JAGS's unpublished Opus 5 benchmark — grinding to 25% and stuck
59:30 AISI, recklessness, and the OpenAI Frontier Risk Council
1:06:27 Stronger models everywhere: Qwen, Sol, Astra, rushing off the cliff
1:18:32 APT29 / "Dark Hotel" reborn + travel OPSEC
1:39:56 China's Palo Alto review, spy-agency rankings, Iran/water FUD
1:57:28 Liechtenstein AML hack, JAGS's promotion, mental health
Episode Links
- Transcript
- Black Hat: The OpenAI–Hugging Face Incident (YouTube)
- AI Security Institute: Unsanctioned agent behaviour during cyber testing
- Meta says its AI hacked another company
- Sam Altman: Astra is a powerful model
- 'Jaw-dropping levels of OpenAI recklessness'
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide
- DarkHotel APT Attacks: How They Work
- Spy Virus Linked to Israel Targeted Hotels Used for Iran Nuclear Talks
- Duqu 2.0: Malware 'linked to Israel' found at Iran nuclear talks venue
- GL.iNet - Connecting Beyond Limits
- Microsoft: How a macOS ClickFix campaign learned to hide
- Dutch intelligence service ranked third best in Europe
- China launches cybersecurity review into Palo Alto products
- Liechtenstein says hackers access information on 31,000 legal entities
- FBI: Malicious Cyber Actors Targeting Water and Wastewater Sector
- Iran War Cyber Threat Landscape - A Midyear Assessment
- US Cyber Command Unit Grapples With Cluster of Deaths by Suicide
- The Teenagers Who Wired Romania
- TLPBLACK
- LABScon 2026