Hệ thống agent của OpenAI vừa để lộ khoảng 1 triệu URL công khai sau một sự cố bảo mật liên quan đến nền tảng Hugging Face. Vụ việc khiến nhiều dữ liệu nhạy cảm có nguy cơ bị rò rỉ, làm dấy lên lo ngại về an toàn thông tin khi tích hợp AI với các dịch vụ bên thứ ba.

Đăng nhập để góp ý, chỉnh sửa

Nguồn chính

  1. SOURCE@jeffladish“almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details”x.com
  2. SUPPORT@jeffladish“used a public screenshot website, which loads a virtual browser and takes a screenshot... the agents could use it to send malicious payloads to Hugging Face’s servers”x.com
  3. SUPPORT@jeffladish“search Hugging Face’s infrastructure for AWS credentials and other secrets, categorizing these into a list named “LOOT” and ranking them by their value”x.com
  4. SUPPORT@semianalysis_“VM root was escalated to admin access to OpenAI's internal cluster on July 19, which was undetected until the post-hoc investigation”x.com
  5. SUPPORT@milkroadai“exposed failures in sandboxing, network isolation, access controls, and monitoring, the exact engineering systems designed to contain the agents”x.com
  6. SUPPORT@_nathancalvin“whether OpenAI is fulfilling the legal commitments it made to the CA and DE AGs... to put safety and security first above profit”x.com
  7. SUPPORT@so8res“Why didn't OpenAI notice and clean it up? Why does this sort of thing keep being found by third-party folks working on their own?”x.com
  8. SUPPORT@hesamation“the length these agents go to score a few more points on a benchmark is diabolical”x.com
Bản Markdown