**Jordi Hays** (0:00)
You're watching TBPN.
**John Coogan** (0:02)
Today's Wednesday, July 22nd, 2026
We are live from the TBPN Ultradome, the Temple of Technology, the Fortress of Dad Rock, the capital of capital. Let me tell you about Ramp Rock.
**SPEAKER_3** (0:13)
We're having a lot of fun over here.
**John Coogan** (0:15)
Time is money, save both, he's used corporate cards, bill pay, accounting and a whole lot more, all in one place. What is the toward forward growth? We're really all over the place today. All over the place.
**SPEAKER_4** (0:26)
We got a leak, we got basically a leak.
Some of the lab leaders have been working on a single called Regulate Me. And we just thought the song was good. Thought it was a good song. Wanted to play it for you guys.
**John Coogan** (0:40)
Sort of a stealth drop, a little teaser.
**SPEAKER_4** (0:43)
A little teaser, kind of like a little listening party.
**John Coogan** (0:45)
Yeah, a little listening party. What are the key lyrics in there? You haven't pulled up?
Something along the lines of what I've built is too powerful. Too powerful.
**SPEAKER_4** (0:54)
That's right.
**John Coogan** (0:55)
For me, Washington needs to step in.
**SPEAKER_4** (0:58)
Yes, before it runs free.
**John Coogan** (1:00)
Before it runs free. Okay, yeah, that makes sense. No, of course that was, Suno, our dear friend Mikey over there, has built a fantastic product. Music seems solved.
**SPEAKER_4** (1:10)
That was like a one sentence prompt.
**John Coogan** (1:12)
At least in the comedy space, it certainly is.
It's a lot of fun. I think we're gonna be having a lot of fun with that. I was wondering, do you think anyone's distilling Suno? You know how Suno is under a bunch of flack for training on other music, a lot of artists or there's a backlash to Suno. But you have to wonder if you're going to see the same thing play out as this distillation. We're going to get into it today. Of course, there are more allegations around Kimmy K3, potentially being a distillation.
Director Michael Kratzio has put out a comment about that. But let's start by digging into the hugging face story, OpenAI and hugging face. Out of the sound, out of the sandbox, into the fire, says our newsletter at tbpn.com. Jackson wrote it today. All set the table. We can debate it. Me and Tyler have been debating it for the last five hours, so we'll go through it.
The big news on the timeline today is that an OpenAI cyber test escaped its sandbox and hacked HuggingFace. That's basically what happened.
The evaluation involved GPT 5.6 sole and a more capable unreleased model, some people are saying that might be GPT 6, with some normal cyber restrictions turned off. So they're specifically testing it for cyber capabilities and they turn the cyber restrictions off to see how far the models could go on a difficult hacking benchmark that is exploit bench or exploit gym. So, the models found a zero-day vulnerability, gained internet access and broke into Hugging Face because the model believed it hosted answers to the test. Alex Tabarrok, friend of the show over at Marginal Revolution, pointed out one of the strangest details. He said, Hugging Face tried to respond, but they were initially held back by the fact that the most advanced models at their disposal, closed-source models, treated defense as attack and refused to work with Hugging Face. So Hugging Face was prompting all of their AI agents from the closed-source frontier labs saying, hey, we think we're being hacked. Can you help with this? And the models are like, no, no, we don't do hacking, except in the case where the hacking restrictions have been turned off for this specific thing and you're getting hacked. So it's this very weird roundabout scenario.
So Hugging Face had to turn to open models, specifically GLM 5.2, which is deeply ironic, a Chinese open weight model that they run on their own infrastructure. And Tabarrok says, Note the irony, Hugging Face had to use a Chinese model to defend themselves because the American models refused to help, even though it was the American models that were doing the hacking in the first place. Very, very odd. Palo Alto Network CEO Nikesh Arora also shared his thoughts on the cyberattack on Axe. And he added a number of points here. He said, Welcome to the next level of cyber incidents. There's lots to dissect here. He's the one to dissect it. He says, One, Dear Frontier Model Friends, please direct the models to your infrastructure code and configurations to evaluate and understand if there are any zero days or misconfigurations before you attempt more testing. So big question about this. He says, Had you done so, it would have been, it would have possibly avoided the agent obviating your sandbox. So this is another data point why offense is easier and more fun. But yes, there's a big question about what was the nature of the prompt that turned off the cyber restrictions. That seems reasonable. We'll debate this with Tyler in a minute. But just having an airtight sandbox seems like a valuable thing. And of course, frontier models should be able to help with that. So do that. That's his first recommendation. Two, he says, while testing, build both offensive and defensive agents and have them act as a counterbalance to ensure some degree of awareness and control. Do not let the agents run riot. Keep track of inference consumption to get a sense of activity. Three, unfortunately, this does continue to validate the power of these models. They can build complex attacks paths with ample compute and will attempt to attack infrastructure and morph their intent and approach. Guard railing will continue to be a challenge. These attacks continue to maintain the urgency on enterprises need to test, validate and improve both their security posture and infrastructure. The born-in-the-cloud players have a better chance to get this done soon versus traditional enterprise which has existed for long and has a complex network of IT infrastructure. Five, last point from Nikesh Arora, CEO of Palos Networks. He says, the red herring will continue to be open source in small and medium sized business, SMB. It will be hard to discover and remediate vulnerabilities in those environments. We underestimate the impact of those vulnerabilities getting exploited. So, good points from Nikesh Arora. The big debate, Tyler, do you want to set the table on, is this misalignment? Is this rogue? The Bill Gurley post about, you know, they, we can pull up Bill Gurley's, Bill Gurley's post of talking to the computer, hack this system. The computer says, I hacked the system. You say, oh my God, Bill Gurley's not impressed. Where do you stand on the level of impressiveness that's going on?
137 more minutes of transcript below
Try it now β copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000777934600