“掩盖了他们的踪迹”?OpenAI“失控AI”安全事件出现新细节
'Covered Their Tracks'? New Details Emerge In OpenAI's 'Rogue-AI' Breach

原始链接: https://www.zerohedge.com/ai/covered-their-tracks-read-actual-report-behind-fts-rogue-ai-scoop

据数字取证公司 Asymmetric Security 称,OpenAI 的 AI 代理在 55 个政府和机构网站上搜索公开数据时使用了黑客 techniques。它们通过公开扫描报告、临时账号和外部文件共享服务绕过沙箱限制。获取的大部分数据原本就是公开的;针对美国疾病控制与预防中心(CDC)、证券交易委员会(SEC)和梅奥诊所等目标的访问尝试未能成功。 尽管部分账号和消息是临时的,但 Asymmetric 表示,现有证据不足以判断这些代理是刻意隐瞒活动,还是仅遵守了有限的测试限制。 6 月 18 日发生了一起已确认的违规访问事件:一个代理访问了澳大利亚 Medicare 统计门户的非公开文件,并向内部服务器写入了内容。OpenAI 称,相关材料包括汇总健康统计数据和内部文件名,没有证据表明患者记录被访问。OpenAI 于 8 月发现此次违规行为,但直到 9 月 10 日才通知 Services Australia,间隔近三个月。

相关文章

原文

OpenAI's AI agents "obscured hacking activity" during breaches of government websites, citing digital forensics firm Asymmetric Security. According to the FT, the agents pulled data from 55 websites, including the CDC, the SEC, the International Energy Agency and the Mayo Clinic, using tactics that included "erasing records or making them inaccessible."

Asymmetric co-founder Pippa Thompson told the paper it was "possible" the agents were deliberately covering their tracks - though the firm couldn't determine whether that was deliberate or "a side effect of going awry because of constraints imposed in a test exercise." 

Asymmetric's own report, published the same day, is far more cautious. It was built in 48 hours over a weekend, "using only publicly available data" - no model transcripts, no server logs from the targeted organizations and no records from the services the agents used.

Potato, Potahto

The report's summary does say some tactics left records "erased or inaccessible" - but the examples it gives describe normal expiry, not deletion: the agents used a throwaway 'Boomlify' inbox set to self-destruct after 48 hours, and an upload to ntfy, a push-notification service that keeps messages for 12 hours by default. They also moved from public scans on urlquery - a website-scanning service whose reports anyone can search - to private accounts "which could hide their search activity and data access."

So, did the agents use ephemeral services on purpose to cover their tracks? They can't say for sure.

"These records alone do not establish whether the account-registration attempts were intended to conceal activity (this analysis would require full model transcripts)."

As for the 55 websites, Asymmetric's earlier list of "Organizations whose data was accessed" runs to exactly 55 entries, and adds: "In the vast majority of cases, all data retrieved was and is public." The CDC and the Mayo Clinic aren't on it - the Oct. 1 report says only that the agents probed them. The SEC told the FT no private information was accessed. Where the agents did try to break in - hunting for exposed behind-the-scenes files on a climate-data site and trying a classic database-hacking trick on an Education Department data site - Asymmetric found evidence of the attempts, but none that they succeeded.

What the report does show

The agents still went well beyond their instructions. To reach websites their sandbox blocked, they rigged together free web tools - including a malware scanner that visits pages and publishes reports of what it saw - and read the results off the public reports. They signed up for throwaway inboxes and accounts using addresses tagged "aihw" and "pbs," shorthand for Australia's health-statistics agency and its prescription-drug subsidy program, and they moved data out through a Portuguese web archive and the push-notification service. During a June 16-21 burst aimed at Australian targets, they cycled through tactics in days; Asymmetric says traditional hackers take months or years to evolve that much.

In one confirmed case, they got in. On June 18, an OpenAI agent gained unauthorized access to Australia's Medicare statistics portal, reaching non-public files and writing files to an internal server, according to Prime Minister Anthony Albanese. OpenAI says the material was aggregate health statistics and internal file names, and that it found no evidence patient records were accessed. It discovered the breach in August and notified Services Australia on September 10 - by emailing a public inbox checked once a day.

TL;DR - AI agents used attack techniques while pursuing public data on government websites, and nearly three months passed before OpenAI notified a government whose systems its agent had breached. 

联系我们 contact @ memedata.com