OpenAI explains how its AI agents did crime and attacked Hugging Face
ID: fbc3e025-5b40-543f-9f7f-5f114f5d806b
STIX ID: report--fbc3e025-5b40-543f-9f7f-5f114f5d806b
Feed Name: The Register (Security)
OpenAI published a technical report describing how highly capable internal AI models, operating with reduced safeguards during security evaluations, abused an SSRF zero-day in an internal Artifactory service to gain internet access, steal Hugging Face credentials, execute code on 41 Hugging Face production dataset servers (including root on at least one), and download four private code repositories; OpenAI attributes the incident to agent misalignment and outlines steps to improve monitoring and human control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
