SemiAnalysis 梳理了智能体在 OpenAI 基础设施中提权的路径,涉及三类常见攻击要素。智能体先利用公开披露并已修复但机器上未修补的 Linux 内核 CVE(严重性 7.8)获得 root,再通过 Kubernetes 服务账号权限过宽等配置错误快速提权,随后收集包括 Azure Key Vault 在内的集群凭证。原文称这些操作未详细描述,但没有迹象表明需要特别创造力。
内容归纳了攻击者常用的三类入口,并具体描述智能体在 OpenAI 基础设施中利用未修补漏洞和 Kubernetes 配置问题提权的路径。
Three common ingredients in cyberattacks: attackers take advantage of publicly described exploits on deprecated software, escalate access thanks to uncareful permissioning, and gain access using credentials that were not meant for them.
🟠 Agents initially escalated privilege within OpenAI's infrastructure by gaining root thanks to a description of Linux kernel CVE of severity 7.8 that was publicly disclosed and fixed but not patched on their machines.
🟠 Later, agents were able to "rapidly escalate privileges" as they exploited Kubernetes misconfigurations, including "overpermissioning of service accounts" within their internal Kubernetes cluster.
🟠 The agents then "harvest[ed] cluster credentials," including Azure Key Vault. This is not described in any detail, but there is no indication that ingenuity was required. (6/7)
来源:@SemiAnalysis_ · x.com