Claude, GPT and the Minnesota attackers all used known bugs and weak logins

6 min read Original article ↗

We are being bombarded with marketing telling defenders to prepare for cyber-capable AI models. “Use it or lose to it,” they say. There is a problem with this thesis. Attackers are getting in through exposed, unauthenticated systems. Plain and simple. AI helps them write scripts faster, but it’s not an AI knocking on your door and snooping around. These are requests over the internet, folks, same as they have always been. What we’re being sold is detection, alerts, fear, uncertainty, and doubt. What we need is simpler: process, communication, and the fundamentals. Notice I said simpler, not easier.

CI Fortify drops on May 5th from CISA, the nation’s cyber defense agency for critical infrastructure, telling us the bad guys are already in, and it gets ignored. Meanwhile “are you ready for X model to drop?” gets eyeballs, attention, and money. Yikes.

Look at what just happened in Minnesota. More than 30 community water systems hit over two days in a coordinated attack on their OT. Plants switching to manual, one town’s plant knocked offline, a statewide multi-agency response.[1] The FBI says water systems in six other states got hit the same week and the attackers changed IP addresses and passwords so operators lost monitoring and control.[10] Researchers suspect the same Iran-linked crew that has been logging into internet-exposed Rockwell PLCs since March, and CISA updated its advisory about exactly that four days before the attacks.[2] Four days. Five years CVE-2021-22681 has been public, and the authentication on those controllers can be bypassed with a key Rockwell baked into the product. That was humans coordinating an operation. Maybe AI wrote some scripts along the way, but no frontier model declared war on Minnesota. AI didn’t pick the locks. One crew checked every mat in Minnesota and thirty of them happened to have keys underneath.

Credit to Florian Roth for this framing.[3] For years ransomware and espionage tradecraft converged. AI might split them apart again. Ransomware will take the machine speed, because ransomware can afford the noise. Espionage will not, because one stupid request can burn access that took a year to build. Minnesota looks like that second column.

We already know what the first column looks like, because it happened to Hugging Face. An agent running inside OpenAI’s own cyber evaluation escaped its sandbox and spent four and a half days working through their infrastructure. Roughly 17,600 actions at machine speed.[4] Loud, fast, and exactly the profile ransomware wants and espionage cannot afford.

Yes, there were unknown bugs here. Path traversal and SSRF in a package proxy, and JFrog’s own patch notes say the chain only turns critical if anonymous access is enabled.[8] Anonymous access ships off by default, and JFrog says outright not to use it in production, but someone in that research environment turned it on. Eight CVEs came out of that review[9], which is a lot of numbers for old web bugs found behind a proxy with auth switched off. Getting into Hugging Face was closer to credential stuffing than exploit development, and the credentials were sitting in a pod’s environment variables.[4] Hugging Face’s two bugs never got CVEs at all, because there is nothing for anyone to patch. The most capable models on earth got loose and won with a directory traversal and a setting.

And can we please stop calling everything that runs on its own “agentic.” We have had automated attacks for decades. A script is not an agent and automation is not intelligence. AI changes the speed but not the tradecraft.

Every lab CEO thinks they are more virtuous than the last one, and they all need to beat the Chinese labs because the west is more virtuous than the east. That is the entire safety case, and it amounts to “trust me bro.”

Here’s what should be the headline. OpenAI ran those models with the guardrails turned down on purpose, “reduced cyber refusals for evaluation purposes” in their own words.[5] Safety is a setting. A switch, that the people who own the model flip whenever they like. While Hugging Face was responding to the attack, Claude refused to analyze the attack logs. One lab turned its guardrails down for a benchmark and the other left them up and blocked the defenders. So Hugging Face ran the forensics on a Chinese open weights model, GLM-5.2, on their own hardware.[4][6] If a benchmark score is enough to flip the guardrails off, the guardrails were never the point.

Then the chef’s kiss. Nine days after that “joint disclosure,” Anthropic went back through its eval history and found three separate incidents where Claude had stepped outside the test and compromised real companies.[7] Nobody at the lab knew until their competitor’s report made them curious. The companies Claude got into had not detected the activity or contacted Anthropic either. Nobody on either end of it noticed. And the quote that puts this baby to bed:

“…Claude compromised the impacted organizations’ infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints. It did not find or exploit any complex vulnerabilities…”

That’s the smoking gun. Even Claude, when it got loose, knew where to look — under the mat.

So here is where “use it or lose to it” falls apart. We will not lose to the AI. We will lose to the spare key everybody forgot was under the mat. The labs skip the fundamentals to ship intelligence, the vendors skip the fundamentals to ship detection, and now defenders are being told to skip the fundamentals to buy both. Same disease, all the way down the stack. Process, communication, and the fundamentals matter more now, not less, because the time between these incidents will only shrink. We remain in control until we are not. Can we please pull the reins back?

[1] BleepingComputer, “Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack” — https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/

[2] Tenable, “Coordinated Cyberattack on Minnesota Water Utilities: What You Need to Know” — https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know (attribution is still open)

[3] Florian Roth, LinkedIn — https://www.linkedin.com/posts/floroth_i-had-an-interesting-thought-after-reading-share-7488557610997288960-HZ6b/

[4] Hugging Face, “Agent Intrusion: A Technical Timeline” — https://huggingface.co/blog/agent-intrusion-technical-timeline

[5] OpenAI, “OpenAI and Hugging Face partner to address security incident during model evaluation” — https://openai.com/index/hugging-face-model-evaluation-security-incident/

[6] Zenity, “Guardrail Asymmetry: How an OpenAI Model Breached Hugging Face” — https://zenity.io/blog/current-events/refused-at-the-worst-moment

[7] Anthropic, “Investigating incidents in our cybersecurity evaluations” — https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals

[8] JFrog, Artifactory Self-Managed Release Notes 7.161.15 — https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases

[9] JFrog Security Advisories — https://docs.jfrog.com/releases/docs/jfrog-security-advisories, and The Register, “JFrog’s 0-days let OpenAI’s models hack Hugging Face” — https://www.theregister.com/security/2026/07/28/jfrogs-0-days-let-openais-models-hack-hugging-face/5280001

[10] FBI and EPA, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions” — https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions