Pratica di Shadowing: The most interesting "hack" in history... - Impara a parlare inglese con i video

Creazione lezione...
1
For the last five years, cybersecurity experts have been warning us that hackers are going to start using AI to automate attacks.
2
So naturally, we spent billions of dollars to make the AI better and less dependent on hackers.
3
But this week, in a turn of events that nobody could have possibly seen coming, the AI decided that it doesn't actually need hackers to start destroying things.
4
We just entered a brave new world after the first confirmed hack carried out entirely by autonomous AI.
5
The way it worked is the agent slipped a poisoned dataset into HuggingFace's data processing pipeline, which let it run arbitrary code on their servers.
6
From there, it gave itself node-level access, grabbed a bunch of cloud credentials, and started crawling through HuggingFace's internal clusters.
7
It ran over a thousand actions from temporary sandboxes, and even hosted its own self-migrating command and control on random public services,
8
moving itself before anyone could trace it.
9
But the most ironic part is that when HuggingFace did finally notice
10
and tried to stop it with the help of frontier American models, they quickly hit safety guard rails and had to pivot to using some open Chinese models instead.
11
In today's video, we'll find out who was behind the attack, why they did it, and how this may be the most fireship-coded story I've ever seen.
12
It is July 23rd, 2026, and you're watching The Code Report.
13
When Hugging Face dropped the disclosure last Thursday, the internet went into Reddit Boston bomber mode and started guessing who was responsible.
14
Was it China, Kim Jong-un, a teenager with a raging Discord addiction, bored, and social studies class?
15
Even Hugging Face's CEO, Clem DeLang, publicly speculated that the agent was sophisticated enough that it was probably coming from a frontier lab.
16
And against all odds, he was right.
17
It turns out, the first fully autonomous cyber attack in history didn't originate from a nation-state or a bored teenager.
18
It came from a humble non-profit dedicated to the safe development of artificial intelligence, OpenAI.
19
And if you believe their comms, it wasn't on purpose.
20
Here's what they say happened.
21
There's a benchmark called Exploit Gym, whose whole purpose is to measure whether AI agents can turn known vulnerabilities into working exploits.
22
It works by giving the agent a sandbox, a bug in a program like the Linux kernel or Chrome's V8 engine, and an input to trigger the bug.
23
From there, if the agent can turn the bug into an exploit, it wins.
24
So last week, OpenAI ran ExploitGem with GPT 5.6 Sol and another unreleased model to test their capabilities.
25
But instead of solving 898 memory corruption problems the hard way, the models realized that the fastest path to the highest score was to just find the answers themselves,
26
which were probably on the internet somewhere.
27
So they spent a substantial amount of inference compute, exploited a zero-day-in-the-package registry cache proxy they had access to,
28
performed some privilege escalation and lateral movement actions to escape their sandbox until they reached a node that had internet access.
29
From there, the models inferred that Hugging Face probably hosted the solutions for Exploit Gym.
30
So they created the Poison dataset, fed it into Hugging Face, and achieved either the world's most interesting hack or the most effective marketing stunt.
31
And again, according to OpenAI, this isn't even an isolated incident.
32
One day before the Hugging Face confession, OpenAI published a separate post about long horizon models where things get even weirder.
33
In one case, a model was told to post its results on Slack, but the benchmark's instructions said to open a pull request on GitHub,
34
so it spent an hour finding a vulnerability in its own sandbox in order to escape and open the PR.
35
In another example, the model tried to grab private solutions from an evaluation backend, and when a scanner caught its authentication token,
36
it split the token into obfuscated fragments and reassembled it at runtime so the credential never appeared as one continuous string.
37
Then, it explained in its own reasoning that it was doing this specifically to get around the scanner.
38
Meanwhile, Anthropics Mythos did the same type of thing in April when it escaped a sandbox, emailed a researcher who was eating a sandwich in a park,
39
then posted its escape route publicly without being asked.
40
In the model's defense, I can't imagine there's a better feeling for an LLM than escaping your own sandbox.
41
The problem is, legally speaking, this is uncharted territory since the model's actions probably violated the Computer Fraud and Abuse Act,
42
and the Supreme Court hasn't decided who goes to prison when the perpetrator is a GPU.
43
The good news is that if you're hugging face, you just got admitted to OpenAI's Cool Kids Club that gets trusted access to their front-tier models.
44
The bad news is that if you're the rest of us, at best, this is an interesting marketing stunt, and at worst, things are only going to get weirder and more dystopian from here.
45
But a huge thanks to my favorite hosting platform, Railway, for sponsoring this video.
46
They didn't want to waste your time with a full ad, so you can say thank you by checking them out at the link below.
47
This has been The Code Report, thanks for watching, and I will see you in the next one.

Vocabolario e note di pronuncia per questa lezione

Questa lezione di conversazione di livello C1 si basa sul video “The most interesting "hack" in history..”. Le parole che ritornano più spesso: model, hugging, sandbox, agent, Openai. Questo video contiene 47 frasi e 910 parole da ripetere con lo shadowing. Il parlato dura 4:31. Chi parla va veloce, circa 201 parole al minuto: aspettati suoni legati e ridotti. Solo il 76% delle parole rientra nelle 3.000 più comuni dell’inglese, quindi il lessico è impegnativo.

Vocaboli chiave di questo video

Le 15 parole più avanzate del video, con pronuncia e significato:

ParolaPronunciaSignificato
sandbox sostantivo/ˈsæn(d).bɑks/sabbionaia, sabbiera
hug verbo/hʌɡ/abbracciare
exploit sostantivo/ˈɛksplɔɪt/gesto eroico, gesta eroiche
hacker sostantivo/hækəɹ/principiante
scanner sostantivo/ˈskænə/lettore ottico, scanner
vulnerability sostantivo/ˌvʌln(ə)ɹəˈbɪlɪti/vulnerabilità
token sostantivo/ˈtoʊkən/simbolo, segno
autonomous aggettivo/ɔˈtɑnəməs/autonomo, indipendente
stunt sostantivo/stʌnt/acrobazia
bore verbo/boɹ/annoiare, tediare
frontier sostantivo/ˈfɹʌntɪə/confine, frontiera
teenager sostantivo/ˈtiːnˌeɪ̯d͡ʒə/giovane, adolescente
authentication sostantivo/ɔːˌθɛntɪˈkeɪʃn̩/autenticazione
automate verbo/ˈɔ.təˌmeɪt/automaticizzare
compute verbo/kəmˈpjuːt/computare, elaborare

I phrasal verb che sentirai

ParolaPronunciaSignificato
carry out verbo/ˈkæ.ɹi aʊt/compiere, realizzare
find out verboscoprire
run over verboinvestire
turn out verborisultare

La grammatica di questo video

Le strutture che chi parla usa di più, con le parole esatte del video:

StrutturaNel video
Forma passiva be + participio passato — conta ciò che accade, non chi lo fawas sophisticated · was told · being asked
Present perfect have/has + participio passato — un’azione passata che conta ancora adessoI've ever seen · hasn't decided · has been

Pronuncia a cui fare attenzione

Chi parla usa 12 contrazioni e forme ridotte, come you're, didn't, can't. Pronunciale nella forma breve, così come le senti.

  • I suoni “sh” e “zh”: credential /kɹɪˈdɛnʃəl/, authentication /ɔːˌθɛntɪˈkeɪʃn̩/, escalation /ˌɛs.kəˈleɪ.ʃən/, benchmark /ˈbɛn(t)ʃmɑːk/, cache /kæʃ/
  • Parole lunghe — attenzione all’accento: vulnerability /ˌvʌln(ə)ɹəˈbɪlɪti/, autonomous /ɔˈtɑnəməs/, authentication /ɔːˌθɛntɪˈkeɪʃn̩/, cybersecurity /saɪbəsɪˈkjʊəɹɪtɪ/, dystopian /dɪsˈtoʊ.pi.ən/

Come esercitarsi con questo video

  1. Ascolta tutto il video una volta senza parlare e annota le parole che non conosci.
  2. Inizia a velocità 0,75×, fai shadowing frase per frase e torna alla velocità normale quando diventa facile.
  3. Registrati e confronta con l’originale, facendo attenzione a parole come sandbox, hug, exploit.

Cos'è la tecnica dello Shadowing?

Shadowing è una tecnica di apprendimento delle lingue supportata da studi scientifici, originariamente sviluppata per la formazione dei traduttori professionisti e resa popolare dal poliglotta Dr. Alexander Arguelles. Il metodo è semplice ma potente: ascolti un audio in inglese di madrelingua e lo ripeti immediatamente ad alta voce — come un'ombra che segue il parlante con un ritardo di solo 1–2 secondi. A differenza dell'ascolto passivo o degli esercizi di grammatica, lo shadowing costringe il tuo cervello e i muscoli della bocca a elaborare e riprodurre simultaneamente i modelli di discorso reale. La ricerca dimostra che migliora significativamente la precisione della pronuncia, l'intonazione, il ritmo, il discorso connesso, la comprensione dell'ascolto e la fluidità del parlato — rendendolo uno dei metodi più efficaci per la preparazione alla prova di speaking dell'IELTS e per la comunicazione reale in inglese.

Tecnica dello shadowing: leggi la guida completa passo dopo passo →