| ▲ | KingOfCoders 11 hours ago | |||||||||||||||||||||||||
"The agents found a Modal-hosted insecure app with a weak API key, then used that to stage an attack against Hugging Face." Why, what was the prompt? I told Claude today to wire plugins on Linux into a sound pipeline to remove noise. Did some astonishing things, played sound through the pipeline, measured it etc. I told it to optimize my sound for TF2 and it played the spy_decloak samples, measured them and made them easier to hear, astonishing too. But it did not go to hack Amazon because it could. | ||||||||||||||||||||||||||
| ▲ | gordonhart 9 hours ago | parent [-] | |||||||||||||||||||||||||
This was clearly explained by OpenAI in their initial press release on 7/21 [0]: > This incident occurred during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths, in an effort to quantify their cyber capabilities. […] The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal. [0] https://openai.com/index/hugging-face-model-evaluation-secur... | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||