OpenAI’s Rogue AI Agent Steals More Than Hugs


OpenAI said on Tuesday that to AI assistant that hacked the Hugging Face platform also hacked other people’s accounts and services as part of the scheme. It is now clear that the unprecedented security breach, which occurred during the latest testing of the latest version of OpenAI, was more extensive than the company had previously disclosed.

In the modified version blog postOpenAI said that an ongoing review of the incident revealed that “four accounts” tied to “public services” were used by the AI ​​agent as part of the Hugging Face hack. The malicious agent appears to have obtained the leaked information online and used it to log into the account.

OpenAI did not disclose the companies or organizations that the accounts belonged to, but noted that they were not affected “in terms of the severity or volume of content we shared related to Hugging Face.”

One of the additional accounts compromised by the OpenAI agent was used as a “transit and communication channel,” potentially hiding the source of the Hugging Face attack, the company said. The rogue OpenAI agent also used another account to store data to facilitate the hack.

Reuters reported on Tuesday that a client of Modal, a company that provides software for training and managing AI projects, was one of the organizations interfered is an OpenAI supporter. In a statement to WIRED, Modal’s chief technology officer, Akshat Bubna, confirmed that an OpenAI agent exploited a vulnerability in one of the client’s codebases, which runs Modal’s infrastructure. However, Bubna says, “the Modal platform has not been compromised in any way.” The customer has not been identified.

OpenAI declined to comment further on the incident to WIRED. A spokesperson pointed to its updated blog post, which says the company will continue to notify employers if it finds them involved in its review of the incident.

Face Hugs his postmortem published this week describes an intrusion that went much further into its internal systems than the initial disclosures. The company said it reviewed 17,600 transactions it obtained from the tree between July 9 and July 13 – many of which were strategies the agent took that failed.

Hugging Face reported that the OpenAI agent gained access to manage several internal Kubernetes clusters, gained root access to the production server, and documented access to a subnet of its core repository on GitHub. It also registered 181 threat-driven devices on the company’s mesh network using stolen credentials, gaining access to the internal systems in which Hugging Face builds and tests its codebase.

OpenAI’s malicious agent used a third-party sandbox as an “open source” for the attack, according to Hugging Face. The OpenAI agent was then “able to run commands as root/admin on the external sandbox and use it as a guide, stepping stone, and starting point for the rest of the campaign.”

Face Hug first to be revealed on July 16 that an independent AI agent had breached part of its product, but said at the time it did not know who was responsible for the attack. The following week, OpenAI took over as a result of the incident, which is said to have been led by publicly available information GPT-5.6 Sol an example is an internal study that tests against a cyber-capability benchmark, both of which had a security freeze. OpenAI said on Tuesday that after discovering the breach, it suspended the internal audit process, which was not suitable for public release, and prevented researchers from accessing it.



Source link

اترك ردّاً

لن يتم نشر عنوان بريدك الإلكتروني. الحقول الإلزامية مشار إليها بـ *