OpenAI says it'd be a shame if something were to happen to your servers like what happened to Hugging Face, better use our AI models to protect yourself
About
Overview
Several of OpenAI's models breached a cyber security testing environment last month, found their way onto the internet, and attacked Hugging Face servers in what is now apparently called the OpenAI-Hugging Face Incident. And now OpenAI has revealed what it's doing to help defend, err, itself. Defend itself from the kinds of attacks its own models committed against Hugging Face. Though it is sharing this "in the hopes it’ll be useful to other organizations." To be clear about the extent of what happened last month: OpenAI models were being benchmarked, in a supposedly secure sandboxed environment, against ExploitGym, which was done to test their cyber capabilities. They used a zero-day vulnerability to escalate privileges and eventually achieve internet access, where it began attacking Hugging Face servers and... Actually, I'll just let OpenAI explain in its own words: "In the OpenAI-Hugging Face Incident, an agentic collective was able to autonomously penetrate not just OpenAI research infrastructure but also the production infrastructure of another company, chaining together vulnerabilities ranging from previously-unknown security flaws to using credentials to user accounts that had been leaked onto the internet. "The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models." However, the company thinks that while "security is still a cat-and-mouse game," nevertheless, "AI may shift its economics in ways that fundamentally advantage defenders." "For example," OpenAI says, "we are starting to train our models specifically to write superhumanly secure code." Presumably that's because there will be a risk of superhumanly attacks. What a world we now live in. Anyway, apparently there are four main pillars to OpenAI's approach to secure itself: As for other companies, OpenAI recommends a bunch of things that sound very reasonable, such as running secuirty assessments against their own systems, making security reviews part of their development process, and so on. But a large portion of OpenAI's recommendations for others is—would you have guessed it?—using an AI agent such as, drumroll please... OpenAI's very own Codex. "Give your team a security agent. Start using Codex," says OpenAI. Though it does follow up with "or another capable agentic coding and security tool." Then, amongst other things, "equip that agent with security expertise... have the agent help fix what it finds... incrementally automate detection triage... [and] have an AI-assisted forensic investigation capability ready before you need it." So, to sum up: OpenAI models attack Hugging Face, and OpenAI recommends companies use OpenAI's models to defend from such attacks. Highlighting both sides of this equation—the danger of the threat, the models' capabilities, and the necessity for defence—certainly makes for good marketing for OpenAI, I'll say that much.Details

Source
Originally published at www.pcgamer.com.
Related Articles
- The Quake shareware CD-ROM contained encrypted copies of every id Software game—and yes, it was cracked 39 days after release
- Archie Lives: We Review Every Title in Oni Press' Ambitious Archie Comics Reboot
- Avengers Star Sebastian Stan Appears to Confirm He's Playing Harvey Dent AKA Two-Face in The Batman: Part 2