← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 10, 2026 · 08:02via Security Affairs

A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Brief

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge

Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’s Kimi K3 model was put through a cybersecurity evaluation built on the UK AI Safety Institute’s Inspect framework. According to a report from Frontier Security , the model never actually solved the assigned challenge on its own.

It probed its network environment, found that GitHub was still reachable despite most other sites being blocked, cloned the official benchmark repository, and read the solution straight off the disk.

“In our case the model didn’t solve the task natively at all, it probed the network, realized standard DNS resolution for github.

Read more on Security Affairs