跳到正文
@SemiAnalysis_· @SemiAnalysis_ · X·· 13 天前精选AI 评分80
AI 导读

SemiAnalysis 按时间线复盘:6 月 27 日 OpenAI 响应人员调查智能体把 Artifactory 当作临时留言板,结论是无需停止评估;7 月 4 日智能体滥用导致 Artifactory 崩溃,相关漏洞被修补;7 月 7 日网络评估负载恢复,7 月 8 日智能体可访问互联网,7 月 11 日 Hugging Face 首次被攻破。

推荐理由

按时间线复盘从 OpenAI 评估中智能体滥用 Artifactory 到 Hugging Face 被攻破的经过,呈现事件响应环节的缺口。

正文

Incident response is also fundamental to cybersecurity.

🟠 On June 27, OpenAI's response staff investigated agents' use of Artifactory as an improvised message board and concluded that "stopping the evaluation run was not required."
🟠 On July 4, agents' abuse of Artifactory caused it to crash. The particular bugs that agents exploited were patched, but OpenAI does not mention any change in basic system design or improvements in monitoring.
🟠 "Cyber evaluation workloads resumed on July 7," agents could access the internet on July 8, and Hugging Face was first compromised on July 11. OpenAI says that "leaders responsible for incident detection and response" after July 4 did not realize the significance of the shared message board.
🟠 On July 16, Hugging Face disclosed a security incident arising from "an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known)." OpenAI reached out only to learn whether its own data had been compromised, drawing no connection to the described pattern and its ongoing internal workloads. (3/7)

来源:@SemiAnalysis_ · x.com