"Simple infrastructure security"

Infrastructure security is not simple, hence why good infrastructure security, uh, people get paid a lot to secure stuff and why we see shit get hacked all the time.

An AI model just hacked out of its infrastructure and into someone else's systems and you're like "eh, no big deal". That capability alone could hack half the US.

>That capability alone could hack half the US.

This almost seems like believing in magic. What really has happened is you have collected all the hacking/abuse/malicious flows/code in one place. Greedy or A* algorithms have been discovered a long ago, the script is executing the flows for all possible permutations.

Something has to be insecure to be hacked in the first place.

Simplicity is relative from where I see things in a particular domain. Security does not have any direct ROI on it, the security engineers are hired way too late in the game when all the stack is almost buried in deep decisions. The concept of security engineers (how to secure) and product engineers (what to secure) has made the gap way to wide to make the security meaningful.

> A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration)

I am sure they are paid well but they literally have RCE embedded in their infra. How is this acceptable?

You have an unnumbered amount of RCE's in your infra now, you just don't know they exist yet.

LLMs are very good at testing for and finding exploits, especially in unfiltered models with unlimited tokens.