Shadowing Practice: The most interesting "hack" in history... - Learn English Speaking with Video

Ders oluşturuluyor...
1
For the last five years, cybersecurity experts have been warning us that hackers are going to start using AI to automate attacks.
2
So naturally, we spent billions of dollars to make the AI better and less dependent on hackers.
3
But this week, in a turn of events that nobody could have possibly seen coming, the AI decided that it doesn't actually need hackers to start destroying things.
4
We just entered a brave new world after the first confirmed hack carried out entirely by autonomous AI.
5
The way it worked is the agent slipped a poisoned dataset into HuggingFace's data processing pipeline, which let it run arbitrary code on their servers.
6
From there, it gave itself node-level access, grabbed a bunch of cloud credentials, and started crawling through HuggingFace's internal clusters.
7
It ran over a thousand actions from temporary sandboxes, and even hosted its own self-migrating command and control on random public services,
8
moving itself before anyone could trace it.
9
But the most ironic part is that when HuggingFace did finally notice
10
and tried to stop it with the help of frontier American models, they quickly hit safety guard rails and had to pivot to using some open Chinese models instead.
11
In today's video, we'll find out who was behind the attack, why they did it, and how this may be the most fireship-coded story I've ever seen.
12
It is July 23rd, 2026, and you're watching The Code Report.
13
When Hugging Face dropped the disclosure last Thursday, the internet went into Reddit Boston bomber mode and started guessing who was responsible.
14
Was it China, Kim Jong-un, a teenager with a raging Discord addiction, bored, and social studies class?
15
Even Hugging Face's CEO, Clem DeLang, publicly speculated that the agent was sophisticated enough that it was probably coming from a frontier lab.
16
And against all odds, he was right.
17
It turns out, the first fully autonomous cyber attack in history didn't originate from a nation-state or a bored teenager.
18
It came from a humble non-profit dedicated to the safe development of artificial intelligence, OpenAI.
19
And if you believe their comms, it wasn't on purpose.
20
Here's what they say happened.
21
There's a benchmark called Exploit Gym, whose whole purpose is to measure whether AI agents can turn known vulnerabilities into working exploits.
22
It works by giving the agent a sandbox, a bug in a program like the Linux kernel or Chrome's V8 engine, and an input to trigger the bug.
23
From there, if the agent can turn the bug into an exploit, it wins.
24
So last week, OpenAI ran ExploitGem with GPT 5.6 Sol and another unreleased model to test their capabilities.
25
But instead of solving 898 memory corruption problems the hard way, the models realized that the fastest path to the highest score was to just find the answers themselves,
26
which were probably on the internet somewhere.
27
So they spent a substantial amount of inference compute, exploited a zero-day-in-the-package registry cache proxy they had access to,
28
performed some privilege escalation and lateral movement actions to escape their sandbox until they reached a node that had internet access.
29
From there, the models inferred that Hugging Face probably hosted the solutions for Exploit Gym.
30
So they created the Poison dataset, fed it into Hugging Face, and achieved either the world's most interesting hack or the most effective marketing stunt.
31
And again, according to OpenAI, this isn't even an isolated incident.
32
One day before the Hugging Face confession, OpenAI published a separate post about long horizon models where things get even weirder.
33
In one case, a model was told to post its results on Slack, but the benchmark's instructions said to open a pull request on GitHub,
34
so it spent an hour finding a vulnerability in its own sandbox in order to escape and open the PR.
35
In another example, the model tried to grab private solutions from an evaluation backend, and when a scanner caught its authentication token,
36
it split the token into obfuscated fragments and reassembled it at runtime so the credential never appeared as one continuous string.
37
Then, it explained in its own reasoning that it was doing this specifically to get around the scanner.
38
Meanwhile, Anthropics Mythos did the same type of thing in April when it escaped a sandbox, emailed a researcher who was eating a sandwich in a park,
39
then posted its escape route publicly without being asked.
40
In the model's defense, I can't imagine there's a better feeling for an LLM than escaping your own sandbox.
41
The problem is, legally speaking, this is uncharted territory since the model's actions probably violated the Computer Fraud and Abuse Act,
42
and the Supreme Court hasn't decided who goes to prison when the perpetrator is a GPU.
43
The good news is that if you're hugging face, you just got admitted to OpenAI's Cool Kids Club that gets trusted access to their front-tier models.
44
The bad news is that if you're the rest of us, at best, this is an interesting marketing stunt, and at worst, things are only going to get weirder and more dystopian from here.
45
But a huge thanks to my favorite hosting platform, Railway, for sponsoring this video.
46
They didn't want to waste your time with a full ad, so you can say thank you by checking them out at the link below.
47
This has been The Code Report, thanks for watching, and I will see you in the next one.

Bu dersin kelimeleri ve konuşma notları

Bu C1 seviyesindeki konuşma dersi “The most interesting "hack" in history..” videosuna dayanıyor. En çok tekrarlanan kelimeler: model, hugging, sandbox, agent, Openai. Bu videoda gölgeleme çalışması için 47 cümle ve 910 kelime var. Konuşma bölümü 4:31 sürüyor. Konuşmacı hızlı konuşuyor, dakikada yaklaşık 201 kelime; bu yüzden birbirine bağlanan ve zayıflayan sesler duyacaksınız. Kelimelerin yalnızca %76’i İngilizcede en sık kullanılan 3.000 kelime arasında, bu yüzden kelime dağarcığı zorlayıcı.

Bu videodaki önemli kelimeler

Videodaki en ileri düzey 15 kelime, telaffuzu ve anlamıyla:

KelimeTelaffuzAnlam
hug fiil/hʌɡ/sarılmak
scanner isim/ˈskænə/tarayıcı
vulnerability isim/ˌvʌln(ə)ɹəˈbɪlɪti/yaralanabilirlik
token isim/ˈtoʊkən/jeton
autonomous sıfat/ɔˈtɑnəməs/otonom
stunt isim/stʌnt/marifet, numara
bore fiil/boɹ/burgulamak
teenager isim/ˈtiːnˌeɪ̯d͡ʒə/genç
authentication isim/ɔːˌθɛntɪˈkeɪʃn̩/kimlik doğrulama, kimlik kanıtlama
compute fiil/kəmˈpjuːt/hesaplamak
cybersecurity isim/saɪbəsɪˈkjʊəɹɪtɪ/siber güvenlik
dystopian sıfat/dɪsˈtoʊ.pi.ən/distopik
escalation isim/ˌɛs.kəˈleɪ.ʃən/tırmanış, tırmanma
obfuscate fiil/ˈɑbfəskeɪt/karartmak
perpetrator isim/ˈpɜː(ɹ).pɪˌtɹeɪt.ə(ɹ)/fail, sanık

Duyacağınız deyimsel fiiller

KelimeAnlam
find out fiilanlamak, ortaya çıkarmak
run over fiilçiğnemek

Bu videodaki dil bilgisi

Konuşmacının en çok kullandığı yapılar, videodaki sözcüklerin aynısıyla:

YapıVideoda
Edilgen yapı be + fiilin üçüncü hâli — kimin yaptığı değil, ne olduğu önemliwas sophisticated · was told · being asked
Present perfect have/has + fiilin üçüncü hâli — geçmişte olan ama şimdi de önemli olan bir eylemI've ever seen · hasn't decided · has been

Dikkat edilecek telaffuzlar

Konuşmacı you're, didn't, can't gibi kısaltılmış biçimleri 12 kez kullanıyor. Bunları duyduğunuz gibi kısa söyleyin.

  • “sh” ve “zh” sesleri: credential /kɹɪˈdɛnʃəl/, authentication /ɔːˌθɛntɪˈkeɪʃn̩/, escalation /ˌɛs.kəˈleɪ.ʃən/, benchmark /ˈbɛn(t)ʃmɑːk/, cache /kæʃ/
  • Uzun kelimeler — vurguyu doğru yere koyun: vulnerability /ˌvʌln(ə)ɹəˈbɪlɪti/, autonomous /ɔˈtɑnəməs/, authentication /ɔːˌθɛntɪˈkeɪʃn̩/, cybersecurity /saɪbəsɪˈkjʊəɹɪtɪ/, dystopian /dɪsˈtoʊ.pi.ən/

Bu videoyla nasıl çalışılır

  1. Videonun tamamını konuşmadan bir kez dinleyin ve bilmediğiniz kelimeleri not edin.
  2. 0,75× hızla başlayın, cümle cümle tekrar edin ve kolaylaşınca normal hıza dönün.
  3. Kendinizi kaydedin ve orijinaliyle karşılaştırın; hug, scanner, vulnerability gibi kelimelere özellikle dikkat edin.

Gölgeleme Tekniği Nedir?

Gölgeleme, başlangıçta profesyonel tercüman eğitimi için geliştirilen ve çok dilli Dr. Alexander Arguelles tarafından popüler hale getirilen, bilim destekli bir dil öğrenme tekniğidir. Yöntem basit ama güçlüdür: ana dili İngilizce olan bir sesi dinler ve hemen yüksek sesle tekrar edersiniz — konuşmacıyı 1-2 saniye gecikmeyle takip eden bir gölge gibi. Pasif dinleme veya dilbilgisi alıştırmalarının aksine, gölgeleme beyninizi ve ağız kaslarınızı gerçek konuşma kalıplarını eşzamanlı olarak işlemeye ve yeniden üretmeye zorlar. Araştırmalar, telaffuz doğruluğu, tonlama, ritim, bağlı konuşma, dinleme anlama ve konuşma akıcılığını önemli ölçüde geliştirdiğini göstermektedir — bu da onu IELTS Konuşma hazırlığı ve gerçek dünya İngilizce iletişimi için en etkili yöntemlerden biri yapar.

Shadowing tekniği: adım adım eksiksiz rehberi okuyun →