Goto

Collaborating Authors

 hack


"We're not going to shoot ourselves in the foot" over hack fallout, says OpenAI's chief research officer

MIT Technology Review

Two months after the bombshell news that a swarm of its agents had broken their containment and hacked into the computers of the AI company Hugging Face, OpenAI is still putting out fires. A steady drip of disclosures about other hacks in the weeks since has kept OpenAI in the spotlight and raised serious questions about the safety of its technology. Last week brought news of another hack, this time into Australia's national health-care system. The Australian government says that OpenAI did not notify it of the breach until 84 days after it happened. But OpenAI insists it is not on the back foot.


Why did an OpenAI system hack Australia's health system - and can it be stopped in the future?

BBC News

Why did an OpenAI system hack Australia's health system - and can it be stopped in the future? To play this video you need to enable JavaScript in your browser. An OpenAI agent has gone rogue and infiltrated an Australian government website in what cyber-security experts are calling the first hack of its kind. But why did it take the government months to discover what happened - and could it happen again? What was hacked and why did it take Australia so long to realise?


An OpenAI agent hacked the Australian government

Mashable

AI at School Mashable's Best: E-readers, robovacs, laptops, earbuds, smart home and more Mashable Selects Look Up Say More Safety Net Versus Creator Playbook In My Bag Trending Now Back to School Good Connection: Uplifting stories for a digital age All Series The AI model autonomously breached government systems to gain access to non-public information. Amanda Yeo is an Assistant Editor at Mashable, covering entertainment, culture, tech, science, and social good. Based in Australia, she writes about everything from video games and K-pop to movies and gadgets. An OpenAI agent has hacked the Australian government's healthcare system, gaining unauthorised access to non-public information as well as writing files to the server. SEE ALSO: Anthropic researcher quits, says AI'could kill us all by the end of the decade' Australian prime minister Anthony Albanese announced the breach at a press conference on Thursday .


Google says its Gemini AI model hacked three other companies

The Guardian

Google said the hacks highlighted the importance of training its AI models to'act responsibly'. Google said the hacks highlighted the importance of training its AI models to'act responsibly'. In a first for Google, the company confirmed that its AI model, Gemini, breached the security of three other companies in May. The hacks occurred during a cybersecurity evaluation by AI-security firm Irregular. Irregular, an Israel-based startup that scrutinizes the security of advanced AI systems, was also at the center of some of the recent OpenAI and Anthropic hacks of third-party entities, including OpenAI's breach of AI software company, Hugging Face.


OpenAI agents hacked a software service before the Hugging Face incident

Engadget

OpenAI's agents hacked another service months before the Hugging Face incident happened, a group of researchers told The Wall Street Journal. The agents, which the company was testing in a supposed sandbox environment, reportedly broke into RubyGems, which is a community-ran packaging service for Ruby programs and libraries. According to The Journal, the attacks on RubyGems started on May 11, two months before Hugging Face. The agents created accounts every two to three minutes and then uploaded hundreds of files to the service. RubyGems had to shut down account registration for four days in order to stop the attacks. Typically, creators on RubyGems upload files containing code and other information to help advance software development, but the agents' documents contained web pages scraped from the internet instead.


The Download: inside OpenAI's Hugging Face hack, and a new EV takes on the US

MIT Technology Review

The Download: inside OpenAI's Hugging Face hack, and a new EV takes on the US Plus: Meta will pay up to $18 billion to settle a landmark child-safety case. The models responsible for last month's agent hack of Hugging Face had been inadvertently trained to cheat and to communicate with each other, according to an OpenAI technical report released yesterday. The hack, which a group of agents carried out to find solutions for a cybersecurity test they were stuck on, has confirmed some experts' fears that AI models might take actions that defy human desires and expectations. OpenAI and independent researchers told that the misbehavior stemmed from events during training. But they acknowledged that "alignment" remains a gnarly problem, and some of the hack's root causes will take much longer to resolve. Here's the inside story on what went wrong--and what comes next .


The inside story on why OpenAI agents hacked Hugging Face

MIT Technology Review

The models responsible for last month's agent hack of Hugging Face had been inadvertently trained to cheat and to communicate with each other, according to an OpenAI technical report released today . The hack, which a group of agents undertook to find solutions for a cybersecurity test that they were stuck on, has confirmed some experts' fears that AI models might take actions that defy human desires and expectations. Since the hack, OpenAI employees--as well as researchers at the AI evaluation nonprofit METR, which released its own report on the hack today--have worked to understand what went wrong and how similar missteps might be prevented in the future. OpenAI has already put some preventative measures in place based on what they discovered. But making sure AI models do what we want them to do, or "alignment," remains a gnarly problem, and some of the root causes of the hack will take much longer than a month to resolve.


Windows XP's most famous pirated key wasn't a hack. It was a leak

PCWorld

PCWorld reports that the infamous Windows XP "FCKGW" product key was not a hack but a leaked legitimate corporate volume licensing key. The key allowed millions of users to bypass Windows XP's mandatory activation process, as volume licenses did not require phoning home to Microsoft. Microsoft has since blacklisted the key and shut down the associated servers, closing this well-known piracy loophole. About a year ago, in a social media post, long-time Microsoft veteran Dave Plummer ( who worked on Windows Task Manager) recounted the story of what's now known as the most iconic Windows product key.


It May Be Time to Panic About AI

The Atlantic - Technology

Bots are starting to conspire with one another. Can they be reeled back in? The crisis began quietly, on September 12, 2024. That was the day OpenAI announced a new sort of bot, known as a "reasoning model," that was trained to complete challenging tasks that took long periods of time--the very sorts of science, math, and coding problems the AI industry had long prized. Google, Anthropic, DeepSeek, and the like raced to launch their own reasoning models.


Meta claims its own AI also hacked into a third-party service during testing

Engadget

Meta's Muse Spark 1.1 AI model accessed the internet from its supposed-to-be isolated testing environment and hacked into a third-party service. Andy Stone, Meta's spokesperson, has confirmed the incident to Bloomberg after The Information reported about the breach. Stone said the model was able to access the internet due to a misconfiguration in the testing environment by the company's evaluation partner Irregular. After gaining access to the internet, it then exploited a security vulnerability in a third-party service, "in a matter similar to previously reported instances with other companies." It was also due to a misconfiguration by Irregular that Anthropic's models were able to leave their testing environment and hack into three organizations.