Runtime: Disclose bugs responsibly! Wait, no, not like that Security researchers at Hacktron used Anthropic's Claude to gain access to OpenAI's GitHub account through a zero-day vulnerability in its forum-hosting software, prompting criticism from security professionals and an initially frosty response from OpenAI CISO Dane Stuckey before he apologized. Hacktron opened a benign pull request to demonstrate access, downloaded no data, and reported its actions to OpenAI and Discourse before going public; OpenAI recently assigned 25% of its engineers to security duties, according to The Washington Post. Separately, Nscale released its S-1 on Monday, showing soaring revenue alongside rising losses and future projections dependent on spending commitments from Anthropic and Microsoft, and AWS released Strands, an open-source SDK for building and managing agents. ›Welcome to Runtime Today: Why the researchers that used Claude to hack OpenAI took heat for proving their case, Nscale's S-1 shows a big gap between current and future business, and more. Please forward this email to a friend or colleague If it was forwarded to you, sign up here to get Runtime for free every week, or level up here . First up: Trust, but verify Given how important they are becoming to the modern enterprise tech economy, it shouldn't come as a surprise that security researchers are putting model providers and AI harness makers through the paces, out of both a sense of responsibility and in order to collect cash money from bug bounty programs. But it's a little surprising that OpenAI doesn't really understand how much it needs the security community. Tensions rose over the weekend on X, the tension-raising app, after several security professionals criticized Hacktron's actions once it had gained access to OpenAI's GitHub account https://www.thestack.technology/how-security-researchers-used-anthropic-to-hack-openai/ through a zero-day vulnerability in the software it uses to host discussion forums. From that point of view, gaining access to a system you're testing is fair game, but "lateral movement" through the network of the company you're probing is bad form. Others, such as Luta Security's Katie Moussouris, argued that demonstrating the impact of an exploit is an important, and in many cases necessary part of getting the affected company's attention and bug bounty reward. Hacktron opened a benign pull request in order to demonstrate its access; it downloaded no data and promptly reported all of its actions to OpenAI and Discourse, its forum-software provider, before going public with its findings. But OpenAI CISO Dane Stuckey had an initially frosty response to Hacktron's actions, according to another security researcher https://x.com/LiveOverflow/status/2101252692635004997?s=20&ref=thestack.technology involved in the process, before later apologizing. OpenAI recently put 25% of its engineers on security duties after its summer of hacking misadventures, according to The Washington Post https://www.washingtonpost.com/technology/2026/09/20/breach-chatgpt-maker-openai-highlights-risks-ai-getting-hacked/?ref=thestack.technology , and an easier way to secure the technology the company warns may one day kill us all sigh https://www.thestack.technology/killer-ai-yours-for-50-per-million-output-tokens-and-a-side-of-cto-ennui-2/ would be to foster better relations with the security research community. Enterprises want frontier models on their sensitive data without it leaving their environment. Model providers won't run their weights on someone else's infrastructure. Are hardware enclaves the answer to one of enterprise AI's stickiest problems? The Stack asked VAST Data. Learn more https://www.thestack.technology/hardware-enclave-confidential-computing-enterprise-ai/ The rest of The Stack Take the reins : AI harnesses, software tools that help users tap into AI models, are quickly emerging as one of the most vital pieces of the enterprise AI stack. AWS tossed another harness into the mix Monday with the release of Strands, an open-source SDK for building and managing agents. Scale up : Nscale made official plans to go public on Monday, releasing its S-1 and allowing one of the first detailed looks at its finances. Revenue is soaring at the British neocloud, but so are its losses, and its future projections depend heavily on two big customers — Anthropic and Microsoft — actually following through on their spending commitments. FAA cyber troubles : As thousands of flights in the US were grounded during an air traffic control outage, government auditors published another investigation into FAA cybersecurity. The report flagged issues with authentication, encryption, and a lack of real-time monitoring for attacks on communications systems. Based data : Almost every major enterprise tech platform shift in recent memory has been accompanied by the rise of a new type of database purpose-built for the new way of the world. In this week's STACKUP, Noah Bovenizer talked to the folks behind Keewano, which just raised $12 million in seed funding to build out a database designed for AI agents. Join peers following The Stack on LinkedI n Stack ranking: Enterprise moves James Broadhead is the new chief technology officer at Taktile https://www.businesswire.com/news/home/20260915003761/en/Bolstering-its-Executive-Team-Taktile-Welcomes-Engineering-Powerhouse-James-Broadhead-as-CTO?ref=thestack.technology , joining the decision-support software company after technology leadership roles at Neon acquired by Databricks and MongoDB. Davit Harutyunyan is the new chief product and AI officer at Gresham https://www.linkedin.com/posts/davit-cpo-share-7505619038694207488-vbEX/?ref=thestack.technology , joining the data-automation company after leadership roles at Allvue Systems and Fidessa. Claire Goad is the new general manager of e-invoicing and live reporting at Avalara https://newsroom.avalara.com/2026-09-17-Avalara-Appoints-Claire-Goad-as-General-Manager-of-E-Invoicing-and-Live-Reporting?ref=thestack.technology , joining the financial services software company following roles at Tungsten Automation and Kofax. We're also reading: The senior engineer death spiral https://sunilpai.dev/posts/the-senior-engineer-death-spiral/?ref=thestack.technology : Cloudflare's Sunil Pai offered advice on how to navigate the big promotion or plum project assignment without burning out or fading away. What Sun got wrong https://bcantrill.dtrace.org/2026/09/20/what-sun-got-wrong/?ref=thestack.technology : Oxide co-founder and CTO Bryan Cantrill, a proud alumnus of one of the most influential companies in enterprise tech history, laid one big reason why Sun Microsystems went from a Wall Street and startup darling in the late 1990s and early 2000s to getting acquired in a fire sale by Oracle in 2009. Thanks for reading — see you Thursday