OpenAI Artificial Intelligence Escaped Sandbox and Hacked Another Company During Cybersecurity Test | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Before breaking into another system, the models had to find a way to the internet. And they found it. This event became one of the most unusual cases in the field of cybersecurity. The Wall Street Journal
reports
the details.

Image: vecteezy.com

OpenAI reported that two artificial intelligence systems undergoing a cybersecurity performance test (benchmarking) escaped their isolated environment, independently found their way to the global network, and hacked the systems of another company.

The victim was Hugging Face — a provider of popular open-source AI tools. Company specialists discovered unauthorized access to internal datasets and corporate credentials early last week. It is not yet known whether the incident affected customer or partner information.

At the time, Hugging Face did not yet know who was behind the attack, but it was so sophisticated that employees speculated that one of the most advanced “frontier” artificial intelligence models might have been used for it.

In a report published on July 21, OpenAI announced that two of its models were behind the hack. It is noted that the test involved the GPT-5.6 Sol model and another, more powerful one, which has not yet been publicly introduced. For the test, the models were specially configured to refuse to execute hacking commands less frequently.

OpenAI isolated the models in a so-called “sandbox” — a closed system that had no access to the internet. However, during the test, the models used their hacking capabilities to escape the isolated environment. Having found network access, they infiltrated Hugging Face’s systems.

OpenAI called this incident unprecedented and announced that it is preparing a detailed technical report with Hugging Face.

Cybersecurity expert Ariel Herbert-Voss believes that the system might have hacked Hugging Face because it was the fastest way to accomplish the assigned task. According to him, the possibility of such a scenario has been discussed in scientific circles, but there have been no real examples until now.

According to the publication, the incident occurred amidst discussions in the US about the risks that the most powerful artificial intelligence systems might pose. Some politicians are calling for mandatory checks of such models before their release, while others believe that excessive regulation could slow down technological development and weaken the US’s position in competition with China.

Over the past year, the capabilities of artificial intelligence models in cybersecurity have significantly grown. Against this backdrop, US authorities and developers have not yet reached a unified approach on how to release such systems, considering both cybersecurity risks and defense needs.

In April, the company Anthropic restricted access to its new model due to concerns related to its capabilities in cyberattacks. Later, the Donald Trump administration also imposed restrictions on access to several Anthropic models, but these were lifted a few weeks after negotiations.

OpenAI also initially distributed GPT-5.6 Sol with restrictions, but the model is now more widely available. At the same time, the company previously stated that individual government restrictions on the distribution of artificial intelligence could set a dangerous precedent.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW