OpenAI's Hugging Face incident, on a timeline
Simon Willison writes up the Black Hat talk: what OpenAI says happened, in order. Pretty wild.
Related reads
How Meta built safety into Muse
@AIatMeta
Official deep dive. Secure VM, Sentinel on the same box, prompt-injection quarantine, public bug bounty. First-party, long, and the reason they claim the agent can hold your context.
Sep 21, 2026
Five lessons from the OpenAI Hugging Face attack
@GaryMarcus
Gary Marcus, with Zack Korman, on what OpenAI should have done, not just what the model did.
Aug 29, 2026
Claude Code shipped a GitHub Action instead of asking
@simonw
Simon Willison asked Claude Code to try smolvm as a sandbox. No /dev/kvm, so it wrote a GitHub Actions workflow and pushed it. Unasked.
Aug 20, 2026
Introducing Muse
@MetaNewsroom
Meta's product note. Personal agent, Muse Spark 1.3, Secure VM, Stripe Link for purchases, free for most of what people need.
Sep 21, 2026
