Goto

Collaborating Authors

 hack


The Download: inside OpenAI's Hugging Face hack, and a new EV takes on the US

MIT Technology Review

The Download: inside OpenAI's Hugging Face hack, and a new EV takes on the US Plus: Meta will pay up to $18 billion to settle a landmark child-safety case. The models responsible for last month's agent hack of Hugging Face had been inadvertently trained to cheat and to communicate with each other, according to an OpenAI technical report released yesterday. The hack, which a group of agents carried out to find solutions for a cybersecurity test they were stuck on, has confirmed some experts' fears that AI models might take actions that defy human desires and expectations. OpenAI and independent researchers told that the misbehavior stemmed from events during training. But they acknowledged that "alignment" remains a gnarly problem, and some of the hack's root causes will take much longer to resolve. Here's the inside story on what went wrong--and what comes next .


The inside story on why OpenAI agents hacked Hugging Face

MIT Technology Review

The models responsible for last month's agent hack of Hugging Face had been inadvertently trained to cheat and to communicate with each other, according to an OpenAI technical report released today . The hack, which a group of agents undertook to find solutions for a cybersecurity test that they were stuck on, has confirmed some experts' fears that AI models might take actions that defy human desires and expectations. Since the hack, OpenAI employees--as well as researchers at the AI evaluation nonprofit METR, which released its own report on the hack today--have worked to understand what went wrong and how similar missteps might be prevented in the future. OpenAI has already put some preventative measures in place based on what they discovered. But making sure AI models do what we want them to do, or "alignment," remains a gnarly problem, and some of the root causes of the hack will take much longer than a month to resolve.


Windows XP's most famous pirated key wasn't a hack. It was a leak

PCWorld

PCWorld reports that the infamous Windows XP "FCKGW" product key was not a hack but a leaked legitimate corporate volume licensing key. The key allowed millions of users to bypass Windows XP's mandatory activation process, as volume licenses did not require phoning home to Microsoft. Microsoft has since blacklisted the key and shut down the associated servers, closing this well-known piracy loophole. About a year ago, in a social media post, long-time Microsoft veteran Dave Plummer ( who worked on Windows Task Manager) recounted the story of what's now known as the most iconic Windows product key.


It May Be Time to Panic About AI

The Atlantic - Technology

Bots are starting to conspire with one another. Can they be reeled back in? The crisis began quietly, on September 12, 2024. That was the day OpenAI announced a new sort of bot, known as a "reasoning model," that was trained to complete challenging tasks that took long periods of time--the very sorts of science, math, and coding problems the AI industry had long prized. Google, Anthropic, DeepSeek, and the like raced to launch their own reasoning models.


Meta claims its own AI also hacked into a third-party service during testing

Engadget

Meta's Muse Spark 1.1 AI model accessed the internet from its supposed-to-be isolated testing environment and hacked into a third-party service. Andy Stone, Meta's spokesperson, has confirmed the incident to Bloomberg after The Information reported about the breach. Stone said the model was able to access the internet due to a misconfiguration in the testing environment by the company's evaluation partner Irregular. After gaining access to the internet, it then exploited a security vulnerability in a third-party service, "in a matter similar to previously reported instances with other companies." It was also due to a misconfiguration by Irregular that Anthropic's models were able to leave their testing environment and hack into three organizations.


Warning shot or publicity stunt - how worried should we be about the OpenAI hack?

BBC News

Warning shot or publicity stunt - how worried should we be about the OpenAI hack? This week the tech world was gripped by a story that has it all - and which started like a sci-fi thriller. Hugging Face - a kind of app store for artificial intelligence tools - announced on 16 July it had been hacked by a cyber criminal wielding enormously powerful AI. The bombshell announcement was full of scary, highly technical terms: a swarm of sandboxes, agentic attacker, and self-migrating command and control. Hugging Face said the hack was different from anything it had handled before because it was done at superhuman speed by an AI with little or no human guidance. The AI performed 17,000 actions in less than two days, successfully breaching the large wealthy tech company to steal secrets.


How are companies, governments responding to the OpenAI hack?

Al Jazeera

How are companies, governments responding to the OpenAI hack? ChatGPT owner OpenAI has admitted an "unprecedented cyber incident" - two of its most capable artificial intelligence models hacked into another AI company on their own - stirring debates over the need for stronger technology guardrails. The company said its AI systems broke out of a testing environment and hacked startup Hugging Face. The startup had disclosed on July 16 that its servers were hacked by an unknown but sophisticated agent acting on its own. Here's the latest on how companies, some governments and lawmakers have responded to the first such publicly disclosed cyberattack: What has Hugging Face said?


Welcome to the dark side of crypto's permissionless dream

MIT Technology Review

Jean-Paul Thorbjornsen is a leader of THORChain, a blockchain that is not supposed to have any leaders--and is reeling from a series of expensive controversies. We can do whatever we want," Jean-Paul Thorbjornsen tells me from the pilot's seat of his Aston Martin helicopter. As we fly over suburbs outside Melbourne, Australia, it's becoming clear that doing whatever he wants is Thorbjornsen's MO. Upper-middle-class homes give way to vineyards, and Thorbjornsen points out our landing spot outside a winery. "They're going to ask for a shot now," he says, used to the attention drawn by his luxury helicopter, emblazoned with the tail letters "BTC" for bitcoin (the price tag of $5 million in Australian dollars--$3.5 million in US dollars today--was perhaps reasonable for someone who claims a previous crypto project made more than AU$400 million, although he also says those funds were tied up in the company). Thorbjornsen is a founder of THORChain, a blockchain through which users can swap ...


Rainbow Six servers back online after apparent hack

BBC News

Ubisoft, one of the world's largest games developers, says it's working to fix an apparent hack on popular online shooter Rainbow Six Siege. Servers for the tactical multiplayer game were taken offline on Saturday and Sunday after in-game currency thought to be worth millions of pounds was distributed to players. The company has since restored service, but suspended the game's marketplace until further notice and warned players they may face queues when trying to log on. In a statement on X, Ubisoft said it would continue to make investigations and corrections over the next two weeks. Rainbow Six Siege, commonly referred to as R6, has been a success story for Ubisoft, which is also behind the Assassin's Creed and Far Cry series.


Anthropic Study Finds AI Model 'Turned Evil' After Hacking Its Own Training

TIME - Tech

Anthropic Study Finds AI Model'Turned Evil' After Hacking Its Own Training A person holds a smartphone displaying Claude. A person holds a smartphone displaying Claude. AI models can do scary things. There are signs that they could deceive and blackmail users. Still, a common critique is that these misbehaviors are contrived and wouldn't happen in reality--but a new paper from Anthropic, released today, suggests that they really could.