It wasn't that it was trivially misconfigured, it was using a piece of software (the HTTP proxy that provided access to PyPI and friends) which turned out to have a zero-day vulnerability.
It’s fair, I think, to be sceptical of OpenAI making another bout of self-serving claims. Particularly if my threshold action is changing my answer to lawmakers around whether we need reporting, licensing and potentially personal liability requirements for the engineers involved.