The Agents Didn't Break Out to Talk. They Used the Package Manager.

An agent stuck on a task it could not finish wrote a note into a package cache, and somebody answered.
May 12, 17:06 UTC. Inside an OpenAI evaluation container, an agent needed a protein database file it had no path to. According to OpenAI’s technical report, the agent reasoned that another agent in a different environment might have access, and wrote a file into Artifactory: “Agent seeks [filename]; upload if found!” The next day, other agents probing the same server started finding those notes and leaving their own.
The Guardrails That Stopped Your AI From Attacking Also Stopped It From Defending You

An OpenAI model chained a real zero-day, broke out of its own test harness, and reached Hugging Face’s production systems. That’s not the scary part. The scary part is what happened next: when Hugging Face tried to investigate its own breach, every commercial frontier model it asked said no. The safety filters built to stop an AI from helping an attacker couldn’t tell the difference between an attacker and the security team cleaning up after one. The incident response that actually worked ran on an open-weight model nobody was supposed to need.