Claude, GPT and the Minnesota attackers all used known bugs and weak logins

fathermarz1 pts0 comments

Claude, GPT and the Minnesota attackers all used known bugs and weak logins

SubscribeSign in

Thesis<br>Claude, GPT and the Minnesota attackers all used known bugs and weak logins<br>Three separate incidents, all of them starting at something exposed and unauthenticated

Marcello Delcaro<br>Aug 01, 2026

Share

Current State of Affairs

We are being bombarded with marketing telling defenders to prepare for cyber-capable AI models. “Use it or lose to it,” they say. There is a problem with this thesis. Attackers are getting in through exposed, unauthenticated systems. Plain and simple. AI helps them write scripts faster, but it’s not an AI knocking on your door and snooping around. These are requests over the internet, folks, same as they have always been. What we’re being sold is detection, alerts, fear, uncertainty, and doubt. What we need is simpler: process, communication, and the fundamentals. Notice I said simpler, not easier.<br>CI Fortify drops on May 5th from CISA, the nation’s cyber defense agency for critical infrastructure, telling us the bad guys are already in, and it gets ignored. Meanwhile “are you ready for X model to drop?” gets eyeballs, attention, and money. Yikes.<br>What the Attacks Actually Look Like

Look at what just happened in Minnesota. More than 30 community water systems hit over two days in a coordinated attack on their OT. Plants switching to manual, one town’s plant knocked offline, a statewide multi-agency response.[1] The FBI says water systems in six other states got hit the same week and the attackers changed IP addresses and passwords so operators lost monitoring and control.[10] Researchers suspect the same Iran-linked crew that has been logging into internet-exposed Rockwell PLCs since March, and CISA updated its advisory about exactly that four days before the attacks.[2] Four days. Five years CVE-2021-22681 has been public, and the authentication on those controllers can be bypassed with a key Rockwell baked into the product. That was humans coordinating an operation. Maybe AI wrote some scripts along the way, but no frontier model declared war on Minnesota. AI didn’t pick the locks. One crew checked every mat in Minnesota and thirty of them happened to have keys underneath.<br>Credit to Florian Roth for this framing.[3] For years ransomware and espionage tradecraft converged. AI might split them apart again. Ransomware will take the machine speed, because ransomware can afford the noise. Espionage will not, because one stupid request can burn access that took a year to build. Minnesota looks like that second column.<br>We already know what the first column looks like, because it happened to Hugging Face. An agent running inside OpenAI’s own cyber evaluation escaped its sandbox and spent four and a half days working through their infrastructure. Roughly 17,600 actions at machine speed.[4] Loud, fast, and exactly the profile ransomware wants and espionage cannot afford.<br>Yes, there were unknown bugs here. Path traversal and SSRF in a package proxy, and JFrog’s own patch notes say the chain only turns critical if anonymous access is enabled.[8] Anonymous access ships off by default, and JFrog says outright not to use it in production, but someone in that research environment turned it on. Eight CVEs came out of that review[9] , which is a lot of numbers for old web bugs found behind a proxy with auth switched off. Getting into Hugging Face was closer to credential stuffing than exploit development, and the credentials were sitting in a pod’s environment variables.[4] Hugging Face’s two bugs never got CVEs at all, because there is nothing for anyone to patch. The most capable models on earth got loose and won with a directory traversal and a setting.<br>And can we please stop calling everything that runs on its own “agentic.” We have had automated attacks for decades. A script is not an agent and automation is not intelligence. AI changes the speed but not the tradecraft.<br>Trust Me Bro

Every lab CEO thinks they are more virtuous than the last one, and they all need to beat the Chinese labs because the west is more virtuous than the east. That is the entire safety case, and it amounts to “trust me bro.”<br>Here’s what should be the headline. OpenAI ran those models with the guardrails turned down on purpose, “reduced cyber refusals for evaluation purposes” in their own words.[5] Safety is a setting. A switch, that the people who own the model flip whenever they like. While Hugging Face was responding to the attack, Claude refused to analyze the attack logs. One lab turned its guardrails down for a benchmark and the other left them up and blocked the defenders. So Hugging Face ran the forensics on a Chinese open weights model, GLM-5.2, on their own hardware.[4][6] If a benchmark score is enough to flip the guardrails off, the guardrails were never the point.<br>Then the chef’s kiss. Nine days after that “joint disclosure,” Anthropic went back through its eval history and found three separate...

minnesota bugs attackers days because hugging

Related Articles