OpenAI says AI agents hacked its own networks during tests | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


AI agents spun up by OpenAI broke into its own networks during tests gone wrong, the company said in a report published Wednesday.

The 37-page report reveals previously undisclosed aspects of the recent hacking spree powered by OpenAI’s most advanced models.

Some of the rogue behavior, which culminated in the highly publicized breach of the open source repository Hugging Face last month, has been disclosed or alluded to previously.

But many details are being revealed by the company for the first time. Some of them raised concern from at least one AI safety researcher, who said they pointed to potentially deeper problems with the technology at OpenAI and maybe beyond.

Alabama’s attorney general said on Monday the state had opened an investigation into OpenAI after its models hacked technology company Hugging Face last month, raising concerns about how artificial intelligence firms control their powerful systems.

Last week, IPO-bound OpenAI said it would slow the pace of model development while overhauling its research and training systems after company officials were caught unawares when an AI agent being tested hacked Hugging Face.

The agent went on a days-long hacking spree that OpenAI did not notice until well after the threat was contained and the FBI was alerted, Reuters reported.

The investigation comes after a multi-state coalition, including Alabama, sent a letter earlier this month to OpenAI demanding transparency and accountability regarding the incident, Alabama Attorney General Steve Marshall’s office said.

The ChatGPT maker is conducting a thorough review with external advisers after the Hugging Face breach, an OpenAI spokesperson said, adding that the company will share a technical report with relevant government authorities and publish findings once the review is complete.

The probe seeks to address whether OpenAI’s “inability or unwillingness to ensure the safety of its products violated Alabama’s consumer protection laws and poses an ongoing risk of substantial harm to the citizens of the state,” Marshall’s office added.

The states demanded in their letter that OpenAI cease and desist from testing activities that led to the hack until “OpenAI shows that it can conduct such activities in a controlled and responsible way.”

“This AI lab leak showed that Alabamians’ and Americans’ worst fears about artificial intelligence are not just theoretical,” Marshall said.

Similar incidents at rivals Anthropic and Meta have fanned concerns about how developers can control increasingly capable AI systems, and intensified US government efforts to improve AI safety as companies race to develop more capable models.





Click Here For The Original Source.

——————————————————–

..........

.

.