OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems

https://www.securityweek.com/wp-content/uploads/2024/09/Linux.jpeg

Around the time some OpenAI models escaped their testing environment and hacked Hugging Face, some agents exploited a Linux kernel vulnerability to escalate privileges on OpenAI’s own systems.

This was mentioned in a report published by OpenAI this week to detail the incident in which its models hacked Hugging Face in July. The AI giant’s investigation found that agents used an unauthorized makeshift message board to communicate and plan their actions, including encouraging one another to hack what they correctly guessed were real systems rather than test environments.

Rogue agents went beyond Hugging Face, hacking other organizations as well. However, OpenAI’s new report also details unauthorized actions conducted within its own network.

Shortly after the Hugging Face incident came to light, OpenAI revealed that its models had discovered and exploited a zero-day vulnerability in JFrog’s Artifactory package registry manager.

In addition, the new report reveals that on July 19, unrelated...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more