jonny@neuromatch.social ("jonny (nonvenomous)") wrote:
If this press release is true, then if I was a hacker who made their money by pwning billion dollar shitshow startups, what I would know is
A) huggingface has no idea what they are doing and is a rich target
B) they cannot respond to threats, the best they can do is ask an LLM to fix it, and even multiple days later are still issuing truly pitiful patches that dance around the vuln
C) since they will just ask GLM 5.2 to fix it, I'll just pre-rehearse all my prompt injections with GLM 5.2 until they stick, and then in my next attack litter the logs with injections and PWN THE WHOLE IR TEAM TOO





