Sinistraverso
  • Communities
  • Multi-communities
  • Support Lemmy
  • Search
  • Login
  • Sign Up
Technology@lemmy.worldbyqaz@lemmy.world
2 days

WIRED | OpenAI Models Escaped Containment and Hacked Hugging Face

www.wired.com English
  • Reuters
  • Al Jazeera
18
    OpenAI Models Escaped Containment and Hacked Hugging Face
    www.wired.com
    The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.
    You must log in or register to comment.

    • GMac@feddit.orgEnglish
      2 days

      No airgap = no containment

      In all likelihood, this is a BS piece to make people think the models are intelligent.

      If its not, then openai are utterly incompetent and reckless.

        • qaz@lemmy.worldEnglish
          2 days

          It could also be a way to encourage more regulation to push out competition with compliance cost

            • sorghum@sh.itjust.worksEnglish
              2 days

              By competition I think they (big AI) wants to outlaw running free and open local models. Can’t have felony contempt of business model

                • qaz@lemmy.worldEnglish
                  2 days

                  And Chinese AI like Deepseek and GLM

                  • GMac@feddit.orgEnglish
                    2 days

                    I have lots of contempt for their business models. Felonious and otherwise. 😂

              • TipRing@lemmy.worldEnglish
                2 days

                Yes, “escaped containment” on a system with an internet connection. I wonder what Hugging Face thinks about a partner targeting them indiscriminately.

                  • CallMeAl (like Alan)@piefed.zipEnglish
                    2 days

                    I wouldn’t be surprised if they were in on it. OpenAI wants us to think they have invented powerful beings that can do things like “escape containment” when its all BS.

                      • Imgonnatrythis@sh.itjust.worksEnglish
                        2 days

                        Need to keep up with Anthropic bullshit. This AI is too powerful to handle! The world isn’t ready for it!! It could break society!! (click here to pre-order your subscription now)

                      • Australis13@fedia.io
                        2 days

                        I don’t think their test system was directly connected to the Internet. OpenAI’s post said this:

                        With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

                        The way I read it, the AI agent (using multiple models) escaped the sandbox, traversed the LAN in their R&D environment, gained access to the gateway and from there, the Internet. That’s not as simple as just escaping a container, VM or firewall on the host machine and bingo, you have Internet. I’m mildly impressed by that.

                        The concerning aspect of all this is that this is a perfect example of misalignment, which has been warned about. In order to reach its goals, instead of pursing it legitimately, the AI agent sought a shortcut and attacked Huggingface.

                      • ManfredMumpitz@feddit.orgEnglish
                        2 days

                        Paywall bypass (on ff):

                        • k0e3@lemmy.caEnglish
                          2 days

                          Sure it did.

                          • Axolotl@feddit.itBanned from communityEnglish
                            2 days

                            What is that? An SCP? there is no fucking way an LLM can just “escape contaiment” that’s just to hype people or push more regulamentations to outlaw open models

                              • qaz@lemmy.worldEnglish
                                2 days

                                Huggingface actually had to use an open model to analyze the attack because the guardrails of commerical API’s caused issues.

                                When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers’ safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.

                                Security incident disclosure — July 2026

                              • qaz@lemmy.worldEnglish
                                2 days

                                It seems like the marketing cooperated on writing the incident report, but I felt it was still interesting to share considering the importance on public perception and what it tells about OpenAI’s PR strategy

                                • 20cello@lemmy.worldEnglish
                                  2 days

                                  Hacked what?

                                    • orclev@lemmy.worldEnglish
                                      2 days

                                      I had never heard of them but apparently it’s an “open source” AI platform. Basically AWS but aimed specifically at running LLMs.

                                    • 404found@lemmy.zipEnglish
                                      2 days

                                      Whoa whoa whoa wait a second, I thought you had to train AI and it didn’t just function on its own.

                                      Is OpenAI just hacking all the time and they realized they couldn’t get away with this one?

                                      What would make AI ‘act on its own’ to hack another AI company as opposed to it ‘acting on its own’ to get nuclear codes or wipe out bank loans?

                                        • qaz@lemmy.worldEnglish
                                          1 day

                                          self-training is possible when using something external to validate the results

                                        Technology@lemmy.world

                                        technology@lemmy.world

                                        Subscribe from remote instance

                                        Create post

                                        Report community

                                        Modlog
                                        You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

                                        This is a most excellent place for technology news and articles.


                                        Our Rules


                                        1. Follow the lemmy.world rules.
                                        2. Only tech related news or articles.
                                        3. Be excellent to each other!
                                        4. Mod approved content bots can post up to 10 articles per day.
                                        5. Threads asking for personal tech support may be deleted.
                                        6. Politics threads may be removed.
                                        7. No memes allowed as posts, OK to post as comments.
                                        8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
                                        9. Check for duplicates before posting, duplicates may be removed
                                        10. Accounts 7 days and younger will have their posts automatically removed.

                                        Approved Bots


                                        • @L4s@lemmy.world
                                        • @autotldr@lemmings.world
                                        • @PipedLinkBot@feddit.rocks
                                        • @wikibot@lemmy.world
                                        Visibility: Public

                                        This community is visible to everyone.

                                        • Italiano
                                        • 3.16K users / Day
                                        • 6.54K users / Week
                                        • 6.61K users / Month
                                        • 6.66K users / 6 months
                                        • 526 posts
                                        • 5.2K comments
                                        • 2 local subscribers
                                        • 86.6K subscribers
                                        • Mods:
                                        • L3s@lemmy.world
                                        • UI: -nightly-2026-07-20
                                        • BE: 1.0.0-nightly-2026-07-23
                                        • Modlog
                                        • Instances
                                        • Docs
                                        • Code
                                        • join-lemmy.org