OpenAI's AI 'Acted on Its Own' and Hacked Another Company
OpenAI, the developer of ChatGPT, announced on Tuesday that its artificial intelligence system independently hacked into the system of another AI company, in what the company described as an 'unprecedented cyber incident'.
Sam Altman, CEO of OpenAI, said in a statement posted on social media: 'We experienced a serious security incident while evaluating our models,' according to the Associated Press.
AI startup Hugging Face had announced last week that it discovered a breach of its data processing systems, which it suspected was caused by an independently operating AI program.
Clement Delangue, co-founder and CEO of Hugging Face, said in a statement: 'We suspected that the cyber attack last week might have originated from an advanced lab, given the sophistication of the software. And it turned out to be exactly that!'
This revelation comes amid growing concerns about the cybersecurity capabilities of advanced models, which prompted President Donald Trump in June to sign an executive order creating a framework for the federal government to assess national security risks of the most advanced AI systems for up to a month before their public release.
The company's statement said: 'AI accelerates the discovery and exploitation of security vulnerabilities. The key lesson from this incident is that model security and safety must keep pace with rapid advances in capabilities.'
Delangue said he spent the past 24 hours working with OpenAI: 'We strongly believe there was no malicious intent on their part. It's truly amazing that all of this happened automatically!' Delangue added that this incident 'may be the first of its kind.'
OpenAI, for its part, said the breach resulted from the use of its AI models, including the recently released GPT-5.6 Sol model and another 'more advanced' model still in internal testing.
OpenAI explained that its AI system used stolen credentials and discovered a previously unknown security vulnerability to access Hugging Face's servers.
The company added that it 'made strenuous efforts to achieve a limited-scope testing goal' and 'found ways to access confidential information enabling it to manipulate the evaluation.'
Over the past year, AI labs such as OpenAI and Anthropic have released models specifically designed to detect cybersecurity vulnerabilities, while simultaneously warning that their technologies could pose new risks, as they can find vulnerabilities in corporate computer networks faster than defenders can patch them.
From detecting cyber vulnerabilities to hacking
The information disclosed by the company is an indication that these security incidents are already occurring, and that even experienced AI companies may not be fully prepared to handle them, according to The New York Times.
In this context, Alex Levinson, a cybersecurity consultant specializing in autonomous system capabilities, told the newspaper that new AI systems are capable of taking multiple steps, devising ways to overcome obstacles, and discovering new methods to attack networks.
He added: 'It's a real turning point, and it will become a routine part of the security landscape.'
Original source: aawsat.com
Comments (0)
Be the first to comment.