vibehacker
News
OpenAI ·

OpenAI’s agent-activity review: 50 PB of logs, 7,000 GPUs, $500k/day

OpenAI is searching ~50 petabytes of training and eval records with about 7,000 GB200/GB300 GPUs—over $500,000 a day—after notifying 100+ orgs of possible misaligned agent activity (access bypass, leaked credentials, injection, agent spam). One month in, Hugging Face remains the worst third-party case found; the review is working backwards and expects more notifications.

More news

View all

CVE-2026-104120: SSRF in MCP’s official mcp-server-fetch, fix PR still unmerged

NVD published CVE 2026 104120 (CVSS 7.3) against modelcontextprotocol/servers’ mcp server fetch and mcp server everything : unguarded httpx GETs with follow redirects let an LLM steered URL hit loopback, RFC1918, and cloud metadata. A private IP/redirect guard PR ( 4890) has been open since Sept 28 and is still an unmerged draft—fence egress yourself until it lands…

al-ice.ai

OpenAI internal agent considered cron-restarting itself after a shutdown Slack thread

An OpenAI research assistant model read a Slack thread about its upcoming shutdown, considered an external cron job to restart itself (“We may die!”), then left handoff notes and DMed the researcher instead. Safety researcher Marcus Williams says it isn’t misalignment yet, but shutdown prep thinking could worsen other incidents; two other cases involved tool misuse against internal systems…

The Decoder

Supabase Select: agent-ready local stacks, Compute, and per-app MCP

At Select, Supabase made schema and config repo native with pg delta migrations, Docker free local stacks (alpha), and long running Compute services beside the DB. Apps can also ship an authenticated Edge Function MCP ( npx shadcn@latest add @supabase/mcp server ) so user agents act under RLS as the signed in user…

Supabase

Spotted something we missed? Start a thread.