4 ms·
Hugging Face incident, Anthropic reporting sandbox escape, AISI reporting models trying to push exploits to the wild
by henryaj 25d ago
Hugging Face incident, Anthropic reporting sandbox escape, AISI reporting models trying to push exploits to the wild
- frabcus 25d agoAlso (and under-reported, so you could easily have missed it) OpenAI's agents got access to K8 admin on their own research cluster. "This escalation also yielded access to OpenAI’s managed cloud Kubernetes service. The agents escalated to Kubernetes cluster-admin and created a privileged host-mounted pod" https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c78... (see section V)
- henryaj 25d agoJust baffles me when people are like "well no-one's died yet". How long until some mission-critical system is compromised, or hackers use LLMs to ransom a hospital chain?
- jeremyjh 24d agoAnd we really only have OpenAI’s word for it that they had no access to their own weights there and didn’t exfiltrate them. No one who knows that incident could suggest it was beyond its capabilities to do that. And we would have never heard about any of this if it wasn’t investigated by an external party (hugging face). It may have happened elsewhere already. It’s not likely to have, but it is very possible this was our last “free” warning.
- account42 24d agoYou do understand that these are PR stunts, right?