OpenAI president Greg Brockman on using frontier models to harden internal security
OpenAI 如何用前沿智能加固自身防御:The Defender's Window
Greg Brockman frames the OpenAI-Hugging Face breach as a preview of how fast threat actors will evolve. An agentic collective autonomously chained zero-days and leaked credentials to penetrate both OpenAI research infra and Hugging Face production. He tested GPT‑5.6 Sol on his personal site: 13 issues found in 15 minutes—missing DMARC, insecure jQuery, unencrypted Cloudflare-to-AWS traffic—and fixed in an hour. OpenAI’s internal defense rests on four pillars; the post details two: Codex security plugin catches and fixes vulns pre-deploy, and models triage nearly all initial security alerts before humans step in. The other two pillars aren’t spelled out. He flags that Z.ai plans to release GLM‑5.3 by end of August, which will likely accelerate the threat landscape further, and urges defenders to act now.
Why it matters: Greg Brockman uses the OpenAI-Hugging Face breach as a case study, then stress-tests his own site with GPT-5.6 Sol — 13 issues in 15 minutes. This isn't a vendor whitepaper; it's a frontier model holder dissecting its own weak spots in public. Not scoring 90+ because the excer...