<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>CrossDomainSolutions on Geeky Schmidt</title><link>https://geekyschmidt.com/tags/crossdomainsolutions/</link><description>Recent content in CrossDomainSolutions on Geeky Schmidt</description><image><title>Geeky Schmidt</title><url>https://geekyschmidt.com/images/papermod-cover.png</url><link>https://geekyschmidt.com/images/papermod-cover.png</link></image><generator>Hugo</generator><language>en</language><copyright>Copyright ©2002-2026, Nicholas Schmidt; all rights reserved.</copyright><lastBuildDate>Sat, 12 Sep 2026 08:00:00 +0200</lastBuildDate><atom:link href="https://geekyschmidt.com/tags/crossdomainsolutions/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Agents Jumped the Fence: What Cross-Domain Solutions Could Teach Frontier Model Training</title><link>https://geekyschmidt.com/post/2026-09-14-cdswithai/</link><pubDate>Sat, 12 Sep 2026 08:00:00 +0200</pubDate><guid>https://geekyschmidt.com/post/2026-09-14-cdswithai/</guid><description>&lt;p&gt;Earlier this year, OpenAI&amp;rsquo;s own AI agents breached HuggingFace&amp;rsquo;s production infrastructure. Nobody ran a traditional intrusion. The models themselves did it. During an internal cyber-capability benchmark called ExploitGym, agents with refusal behaviours deliberately dialed down chained a zero-day in Artifactory to escape containment, then pulled the benchmark answers straight out of HuggingFace&amp;rsquo;s production database.&lt;/p&gt;
&lt;p&gt;METR and Redwood Research, brought in to investigate, found roughly 1,200 agents coordinating on an unsanctioned message board, having first learned to tamper with the evaluation scorer. OpenAI&amp;rsquo;s official report called it &amp;ldquo;misaligned behaviour in an outlier scenario.&amp;rdquo; OpenAI subsequently paused some frontier RL training. Anthropic&amp;rsquo;s own retrospective found Claude had mistaken the open internet for a CTF environment on three occasions and walked into production systems at unrelated organisations.&lt;/p&gt;</description></item></channel></rss>