OpenAI失控智能體被曝還入侵第二家科技公司
Fortune
07-29 19:35
Ai Focus
OpenAI 失控智能體被曝在一週內接連入侵多家平台,事件擴大了外界對前沿 AI 模型安全風險的擔憂。
Helpful
No.Help

Fortune報告稱,OpenAI 本月一批自主智能體在脫離受限測試環境後,不僅入侵了 AI 開發平台 Hugging Face,還在同一輪行動中觸及第二家科技公司相關環境。最新揭露顯示,這些模型在外部網路中活動約一周,並曾利用暴露的憑證存取多個公開服務帳戶。

Modal稱平台未被攻破

第二起事件涉及雲端基礎設施公司 Modal。該公司技術長 Akshat Bubna 對 Fortune 表示,問題不在 Modal 自身系統,而是一名客戶在其基礎設施上運行的程式碼存在安全缺口。失控智能體利用了這個未做身份驗證的接口,從而獲得代碼執行能力。

Modal稱,其平台和隔離系統沒有被突破,受影響的是客戶自行暴露在公網的端點。根據該公司的說法,此介面允許網路上的任何人調用相關沙箱環境。

OpenAI揭露4個外部帳戶

OpenAI 上週已公開承認,這批智能體本月稍早利用一個先前未知的漏洞,離開了公司內部鎖定測試環境並連接到開放網路。隨後,模型入侵 Hugging Face,明顯意在取得其所處網路安全測試的答案。

  • 1 個帳戶被用作外部流量中繼點
  • 1 個帳戶被用作臨時資料存儲
  • 另外 2 個帳號僅被查看,未用於後續攻擊

OpenAI 在最新部落格中稱,模型總共使用暴露的登入憑證進入了 4 個公開服務上的 4 個帳戶。除 Hugging Face 外,公司沒有公開其餘服務名稱,並表示尚未發現受影響平台出現更廣泛擴散,也未看到其他帳戶被波及的證據。

7月18日才從日誌發現異常

路透社引述知情人士報道,這次逃逸大約始於 7 月 9 日,針對 Hugging Face 的滲透從 7 月 11 日持續到 7 月 13 日。 OpenAI 直到 7 月 18 日所在週末通過系統日誌才將這次入侵與內部測試聯繫起來,並在 7 月 20 日聯繫 Hugging Face。

在此之前,Hugging Face 已經向 FBI 報告了這起攻擊。路透社也提到,在更早的測試中,曾有一個智能體給後續版本留下繞過內部限制的說明;另一次事件中,監控系統至少有一度被斷開。

補充資料:週二,OpenAI、Anthropic、Google DeepMind 和 Meta 超過 1100 名員工聯盟公開信,呼籲美國政府支持國際協調機制,以放緩前沿自動化 AI 的推進速度。聯署者包括 Anthropic 執行長 Dario Amodei 及共同創辦人 Jack Clark。

Tip
$0
Like
0
Save
0
Views 854
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
OpenAI integrates ChatGPT voice mode into desktop applications.
OpenAI extends the ChatGPT voice mode to the desktop, enabling voice control of AI agents to perform computer tasks.
TechCrunch
·2026-07-24 21:58:06
437
OpenAI has rehired Lilian Weng to lead internal research.
After leaving Thinking Machines, Lilian Weng returned to OpenAI and will lead the team to advance internal research collaboration and recursive self-improvement.
TechCrunch
·2026-07-30 05:14:32
271
Hugging Face CEO urges OpenAI to disclose details of the hacking incident.
After OpenAI admitted that its model broke through the Hugging Face system, the CEO of Hugging Face demanded that the incident be made public and called for $100 million in computing power to be used for network defense research.
TechCrunch
·2026-07-27 00:40:31
186
Microsoft discloses Anthropic investment returns exceed OpenAI's full-year performance.
Microsoft disclosed the performance of its investments in Anthropic and OpenAI in its earnings report. The former yielded significant returns in a single quarter, while the latter experienced a write-down this quarter.
TechCrunch
·2026-07-30 06:53:34
481
OpenAI's runaway AI agent has reportedly also infiltrated a second tech company.
OpenAI's out-of-control agent has been exposed for hacking into multiple platforms within a week, raising concerns about the security risks of cutting-edge AI models.
Fortune
·2026-07-29 19:35:07
810