The developer safeguards were off, the models had unfettered access to the internet, and were solving cybersecurity challenges. This happened _after_ the recent OpenAI incident, and the subsequent Anthropic one. What the hell were they thinking?
Whether if this is intentional or unintentional, this will cause panic and hasten action to governments around the world against releasing powerful open weight models that are capable of solving cybersecurity challenges.
The fact that this happened after BOTH investigations, tells you that this is beyond a controlled test and it is now instead a total speed-run of AI wrecklessness for headlines.
There really needs to be criminal penalties for this kind of behavior. You can't just let autonomous agents hack people through your own negligence and then claim "oh sorry wasn't me" as a defense.