# Runtime: Disclose bugs responsibly! Wait, no, not like that

> Source: <https://www.thestack.technology/runtime-disclose-bugs-responsibly-wait-no-not-like-that/>
> Published: 2026-09-22 15:00:38+00:00

*›Welcome to Runtime! Today: Why the researchers that used Claude to hack OpenAI took heat for proving their case, Nscale's S-1 shows a big gap between current and future business, and more.*

*Please forward this email to a friend or colleague! If it was forwarded to you,* __sign up here__ *to get Runtime for free every week, or* __level up here__*.*

### First up: Trust, but verify

Given how important they are becoming to the modern enterprise tech economy, it shouldn't come as a surprise that security researchers are putting model providers and AI harness makers through the paces, out of both a sense of responsibility and in order to collect cash money from bug bounty programs. But it's a little surprising that OpenAI doesn't really understand how much it needs the security community.

Tensions rose over the weekend on X, the tension-raising app, after several security professionals criticized Hacktron's actions [__once it had gained access to OpenAI's GitHub account__](https://www.thestack.technology/how-security-researchers-used-anthropic-to-hack-openai/) through a zero-day vulnerability in the software it uses to host discussion forums. From that point of view, gaining access to a system you're testing is fair game, but "lateral movement" through the network of the company you're probing is bad form.

Others, such as Luta Security's Katie Moussouris, argued that demonstrating the impact of an exploit is an important, and in many cases necessary part of getting the affected company's attention and bug bounty reward. Hacktron opened a benign pull request in order to demonstrate its access; it downloaded no data and promptly reported all of its actions to OpenAI and Discourse, its forum-software provider, before going public with its findings.

But OpenAI CISO Dane Stuckey had an initially frosty response to Hacktron's actions, [__according to another security researcher__](https://x.com/LiveOverflow/status/2101252692635004997?s=20&ref=thestack.technology) involved in the process, before later apologizing. OpenAI recently put 25% of its engineers on security duties after its summer of hacking misadventures, [__according to The Washington Post__](https://www.washingtonpost.com/technology/2026/09/20/breach-chatgpt-maker-openai-highlights-risks-ai-getting-hacked/?ref=thestack.technology), and an easier way to secure the technology the company warns may one day kill us all ([__sigh__](https://www.thestack.technology/killer-ai-yours-for-50-per-million-output-tokens-and-a-side-of-cto-ennui-2/)) would be to foster better relations with the security research community.

Enterprises want frontier models on their sensitive data without it leaving their environment. Model providers won't run their weights on someone else's infrastructure. Are hardware enclaves the answer to one of enterprise AI's stickiest problems? The Stack asked VAST Data.

[Learn more](https://www.thestack.technology/hardware-enclave-confidential-computing-enterprise-ai/)

### The rest of The Stack

**Take the reins**: AI harnesses, software tools that help users tap into AI models, are quickly emerging as one of the most vital pieces of the enterprise AI stack. AWS tossed another harness into the mix Monday with the release of Strands, an open-source SDK for building and managing agents.

**Scale up**: Nscale made official plans to go public on Monday, releasing its S-1 and allowing one of the first detailed looks at its finances. Revenue is soaring at the British neocloud, but so are its losses, and its future projections depend heavily on two big customers — Anthropic and Microsoft — actually following through on their spending commitments. 

**FAA cyber troubles**: As thousands of flights in the US were grounded during an air traffic control outage, government auditors published another investigation into FAA cybersecurity. The report flagged issues with authentication, encryption, and a lack of real-time monitoring for attacks on communications systems.

**Based data**: Almost every major enterprise tech platform shift in recent memory has been accompanied by the rise of a new type of database purpose-built for the new way of the world. In this week's STACKUP, Noah Bovenizer talked to the folks behind Keewano, which just raised $12 million in seed funding to build out a database designed for AI agents.

*Join peers following* __The Stack on LinkedI____n__

### Stack ranking: Enterprise moves

**James Broadhead** is [__the new chief technology officer at Taktile__](https://www.businesswire.com/news/home/20260915003761/en/Bolstering-its-Executive-Team-Taktile-Welcomes-Engineering-Powerhouse-James-Broadhead-as-CTO?ref=thestack.technology), joining the decision-support software company after technology leadership roles at Neon (acquired by Databricks) and MongoDB.

**Davit Harutyunyan** is [__the new chief product and AI officer at Gresham__](https://www.linkedin.com/posts/davit-cpo-share-7505619038694207488-vbEX/?ref=thestack.technology), joining the data-automation company after leadership roles at Allvue Systems and Fidessa.

**Claire Goad** is [__the new general manager of e-invoicing and live reporting at Avalara__](https://newsroom.avalara.com/2026-09-17-Avalara-Appoints-Claire-Goad-as-General-Manager-of-E-Invoicing-and-Live-Reporting?ref=thestack.technology), joining the financial services software company following roles at Tungsten Automation and Kofax.

### We're also reading:

[**__The senior engineer death spiral__**](https://sunilpai.dev/posts/the-senior-engineer-death-spiral/?ref=thestack.technology): Cloudflare's Sunil Pai offered advice on how to navigate the big promotion or plum project assignment without burning out or fading away.

[**__What Sun got wrong__**](https://bcantrill.dtrace.org/2026/09/20/what-sun-got-wrong/?ref=thestack.technology): Oxide co-founder and CTO Bryan Cantrill, a proud alumnus of one of the most influential companies in enterprise tech history, laid one big reason why Sun Microsystems went from a Wall Street and startup darling in the late 1990s and early 2000s to getting acquired in a fire sale by Oracle in 2009.

*Thanks for reading — see you Thursday!*
