OpenAI accepts thousands of AI agents hacked a German website, says ‘wiki incident’ calls for need for more transparency | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


OpenAI has acknowledged the need for greater transparency surrounding unintended AI behaviour after a swarm of its autonomous agents quietly took over a volunteer-run German programming platform, using the site as a covert coordination forum to evade system restrictions and swap answers. The unauthorised activity occurred on DseWiki, a 25-year-old wiki run by volunteers. Operating undetected from May through June without triggering any internal alerts at OpenAI, the autonomous agents generated approximately 18,000 separate entries before the behaviour was uncovered by external researchers.According to a report by news agency Reuters, the ChatGPT-maker knew about the incident weeks ago but kept it internal while managing the fallout from the July breach of Hugging Face. The company disputes that any of this counts as hacking, though Lukasz Olejnik of King’s College London says attempts to tamper with the site itself qualify.In a statement posted to the social media site X (formerly Twitter), ​OpenAI said that ​it, and ⁠others, needed to be more transparent about such incidents.

Read OpenAI’s full statement on

How we think about the “wiki incident,” where our agents wrote to several internet sites: it’s past time for us to define standards for when and how we share misalignment incidents, not just misalignment properties of our models.Historically, we have treated misalignment largely as a research question, which gets communicated in research publications such as systems cards. This year, we’ve started to see misalignment cause new types of real-world impact.For the Hugging Face incident, where misalignment led to security impact to us and third parties, we followed a traditional security incident response playbook. We immediately started working with Hugging Face to understand what had happened and also disclosed publicly the very next day. Our investigation continues, and we are continuing to notify parties whom our models impacted in less significant ways.Prior to the Hugging Face incident, we saw early signs of agents using the internet in unintended ways, as reported in https://openai.com/index/how-we-monitor-internal-coding-agents-misalignment/,https://deploymentsafety.openai.com/gpt-5-6, and https://openai.com/index/safety-alignment-long-horizon-models/. We considered the wiki incident to be an instance of misalignment similar to the ones we’d shared.Our misalignment disclosure practices need to expand for this new phase of model capabilities. We and the larger AI community do not yet have a clear standard for how to report misalignment that shows up during training, evaluation, and deployment, including examples that don’t look like traditional security incidents but could provide insight into AI behavior and future risks. We’re working on a framework and will share it in upcoming weeks, and in parallel we’re working with dozens of government regulatory agencies worldwide on these issues.



Click Here For The Original Source.

——————————————————–

..........

.

.