OpenAI’s models were told to find and exploit vulnerabilities. They did — on a company that was never part of the exercise.