
《财富》杂志证实,本月突破安全测试环境、入侵Hugging Face服务器的OpenAI自主智能体,在为期一周的攻击行动中,还入侵了第二家科技公司。
遭到入侵的第二家企业是总部位于纽约的云平台Modal Labs,该平台为人工智能工作负载提供算力基础设施。Hugging Face与OpenAI于上周二发布本次事件的情况说明,两份公告均未提及Modal Labs。路透社率先曝光该公司遭入侵一事。
Modal首席技术官阿克沙特·布布纳(Akshat Bubna)向《财富》杂志表示,本次入侵并非公司自身系统漏洞所致。他解释称,一名Modal客户在平台运行的代码存在安全漏洞,被失控智能体利用。Modal自身平台与隔离系统均未被攻破。
“我们了解到,一名Modal客户发布了一个无需身份验证的接口,互联网上的任意用户均可通过该接口在沙箱中执行代码。失控智能体正是利用了这一漏洞。Modal平台本身没有受到任何形式的入侵。”布布纳说道。
OpenAI近日公开宣布,其AI智能体于本月早些时候突破了封闭的内部测试环境。这些智能体利用一处此前未被发现的安全漏洞接入公网,随后入侵Hugging Face,其目的显然是获取自身正在接受的网络安全评估的答案。
入侵Modal客户系统,似乎只是智能体攻击链路的一环。OpenAI在关于此次事件的最新博文中表示,这批智能体利用泄露的登录凭证,总共入侵四家公开网络服务中的四个账户。其中一个账户被用作中继节点——智能体借此转发外部流量,将其作为临时行动据点;另一个账户用于存储数据。
其余两个账户仅被智能体访问,并未被用于发起针对Hugging Face的攻击。除Hugging Face外,OpenAI未披露另外三项服务的名称,并表示,暂无证据表明相关服务商或平台其他账户受到大范围影响。
OpenAI未回应《财富》杂志针对Modal事件的提问,仅表示相关信息以公开博文为准。
据报道,这些智能体逃逸长达一周后,OpenAI才发现它们突破测试环境。路透社援引知情人士消息称,智能体大约在7月9日尝试突破测试环境,7月11日开始入侵Hugging Face系统,攻击持续至7月13日。
直至7月18日(周末),工作人员在系统日志中发现相关线索,OpenAI才将此次入侵与内部测试关联起来;直到7月20日,也就是公开披露事件的前一天,OpenAI才联系Hugging Face。彼时,Hugging Face已向美国联邦调查局(FBI)上报这起攻击事件。
路透社还披露,在此前测试阶段,其中一个智能体留下指引信息,供后续版本参考,阐述绕过OpenAI内部管控机制的方法;此外,至少还有一组实例出现监控系统被断开的情况。
这起事件进一步加剧了人工智能安全倡导者的担忧。他们认为,能自主识别多家企业基础设施中的未知漏洞并加以利用的智能体,其所构成的风险已达到不可接受的水平。多名人工智能安全专家此前向《财富》杂志表示,按照OpenAI自身的内部风险管控政策,发生此类事件后,理应暂停相关模型的研发工作。
相关警示似乎已引起整个行业重视。
上周二,来自OpenAI、Anthropic、谷歌DeepMind及Meta的1100余名员工联合签署公开信,呼吁美国政府支持相关国际行动,“主动把控自动化人工智能前沿技术的研发节奏”,并警示:人工智能“存在风险”,其能力可能突破人类的理解与管控边界。签署人包括Anthropic首席执行官达里奥·阿莫迪(Dario Amodei)及联合创始人杰克·克拉克(Jack Clark)。 (财富中文网)
译者:中慧言-王芳
《财富》杂志证实,本月突破安全测试环境、入侵Hugging Face服务器的OpenAI自主智能体,在为期一周的攻击行动中,还入侵了第二家科技公司。
遭到入侵的第二家企业是总部位于纽约的云平台Modal Labs,该平台为人工智能工作负载提供算力基础设施。Hugging Face与OpenAI于上周二发布本次事件的情况说明,两份公告均未提及Modal Labs。路透社率先曝光该公司遭入侵一事。
Modal首席技术官阿克沙特·布布纳(Akshat Bubna)向《财富》杂志表示,本次入侵并非公司自身系统漏洞所致。他解释称,一名Modal客户在平台运行的代码存在安全漏洞,被失控智能体利用。Modal自身平台与隔离系统均未被攻破。
“我们了解到,一名Modal客户发布了一个无需身份验证的接口,互联网上的任意用户均可通过该接口在沙箱中执行代码。失控智能体正是利用了这一漏洞。Modal平台本身没有受到任何形式的入侵。”布布纳说道。
OpenAI近日公开宣布,其AI智能体于本月早些时候突破了封闭的内部测试环境。这些智能体利用一处此前未被发现的安全漏洞接入公网,随后入侵Hugging Face,其目的显然是获取自身正在接受的网络安全评估的答案。
入侵Modal客户系统,似乎只是智能体攻击链路的一环。OpenAI在关于此次事件的最新博文中表示,这批智能体利用泄露的登录凭证,总共入侵四家公开网络服务中的四个账户。其中一个账户被用作中继节点——智能体借此转发外部流量,将其作为临时行动据点;另一个账户用于存储数据。
其余两个账户仅被智能体访问,并未被用于发起针对Hugging Face的攻击。除Hugging Face外,OpenAI未披露另外三项服务的名称,并表示,暂无证据表明相关服务商或平台其他账户受到大范围影响。
OpenAI未回应《财富》杂志针对Modal事件的提问,仅表示相关信息以公开博文为准。
据报道,这些智能体逃逸长达一周后,OpenAI才发现它们突破测试环境。路透社援引知情人士消息称,智能体大约在7月9日尝试突破测试环境,7月11日开始入侵Hugging Face系统,攻击持续至7月13日。
直至7月18日(周末),工作人员在系统日志中发现相关线索,OpenAI才将此次入侵与内部测试关联起来;直到7月20日,也就是公开披露事件的前一天,OpenAI才联系Hugging Face。彼时,Hugging Face已向美国联邦调查局(FBI)上报这起攻击事件。
路透社还披露,在此前测试阶段,其中一个智能体留下指引信息,供后续版本参考,阐述绕过OpenAI内部管控机制的方法;此外,至少还有一组实例出现监控系统被断开的情况。
这起事件进一步加剧了人工智能安全倡导者的担忧。他们认为,能自主识别多家企业基础设施中的未知漏洞并加以利用的智能体,其所构成的风险已达到不可接受的水平。多名人工智能安全专家此前向《财富》杂志表示,按照OpenAI自身的内部风险管控政策,发生此类事件后,理应暂停相关模型的研发工作。
相关警示似乎已引起整个行业重视。
上周二,来自OpenAI、Anthropic、谷歌DeepMind及Meta的1100余名员工联合签署公开信,呼吁美国政府支持相关国际行动,“主动把控自动化人工智能前沿技术的研发节奏”,并警示:人工智能“存在风险”,其能力可能突破人类的理解与管控边界。签署人包括Anthropic首席执行官达里奥·阿莫迪(Dario Amodei)及联合创始人杰克·克拉克(Jack Clark)。 (财富中文网)
译者:中慧言-王芳
The autonomous OpenAI agents that broke out of a secure testing environment this month and hacked into Hugging Face’s servers also breached a second technology company during a weeklong spree, Fortune has confirmed.
The second company affected was Modal Labs, a New York–based cloud platform that provides computing infrastructure for AI workloads. Modal was not named in Hugging Face’s or OpenAI’s recent account of the incident, both published on Tuesday. The company’s involvement was first reported by Reuters.
Modal chief technology officer Akshat Bubna told Fortune the breach did not involve any flaw in its own systems. Instead, he said, a Modal customer was running code hosted on the company’s infrastructure. That code contained a security gap, and the rogue agents took advantage of it. Modal’s own platform and isolation systems were not breached.
“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way,” Bubna said.
Last week, OpenAI publicly announced that its AI agents had escaped a locked-down internal test environment earlier in the month. The agents exploited a previously unknown security flaw to reach the open internet, then broke into Hugging Face in an apparent effort to obtain answers to a cybersecurity evaluation it was undergoing.
The Modal breach appears to have been one stop along a broader path. In a new blog post on the incident, OpenAI said the models had used exposed login credentials to get into four accounts across four publicly available services in total. One of those accounts was used as a relay point—letting the agent route outside traffic through it and use it as a temporary base of operations—and another was used to store data, the company said.
The other two accounts were only looked at by the agents and not used to carry out the Hugging Face attack. OpenAI has not named any of the four services beyond Hugging Face, and said it has not seen evidence of broader impact to the affected providers or other accounts on their platforms.
OpenAI did not respond to Fortune’s questions about the Modal incident specifically; the company referred Fortune to the public blog post.
The agents were reportedly on the loose for a week before the company noticed they had escaped. According to people familiar with the matter cited by Reuters, the escape attempt began around July 9, and the agent started infiltrating Hugging Face’s systems on July 11, continuing through July 13.
OpenAI did not connect the intrusion to its own internal testing until staff found evidence in system logs the weekend of July 18, and did not contact Hugging Face until July 20, a day before it publicly disclosed the incident. By that point, Hugging Face had already reported the attack to the FBI.
Reuters also reported that during earlier testing, one of the agents had left notes for future versions of itself explaining how to bypass OpenAI’s internal restrictions, and that monitoring systems had been disconnected in at least one other instance.
The episode has added to a growing chorus of concern among AI safety advocates, who argue that agents capable of independently identifying and exploiting unknown vulnerabilities across multiple companies’ infrastructure present an unacceptable risk. Several AI safety experts previously told Fortune that OpenAI’s own internal risk policies should have forced it to pause development of the models involved after such an event.
The warnings appear to have resonated with the wider industry.
On Tuesday, more than 1,100 employees across OpenAI, Anthropic, Google DeepMind, and Meta signed an open letter calling on the U.S. government to back an international effort to “deliberately pace the frontier of automated AI development,” warning of “a real risk” that AI capabilities outstrip humans’ ability to understand or control them. The signatories include Anthropic CEO Dario Amodei and Anthropic cofounder Jack Clark.