The vuln that was exploited was a well-known hdf5 security problem rolled together with amateur-hour kubernetes config. This is something that an LLM should be able to do because its just pattern matching all the blog posts that say "this is bad to do" with the hf code.
https://neuromatch.social/@jonny/116962763699983489
OpenAI wants to sell this as "omg our models are so smart they are this dangerous swarm intelligence" but in reality the story is "LLMs are so fundamentally insecurable that any string left anywhere in reach is an unmitigatable prompt injection"