Part of The AI Control Crisis · 15 stories · since Sep 3 · newest 19m ago
Researchers use Anthropic's Claude to hack into OpenAI's internal systemsOpenAI confirms responsibility for the RubyGems attack
2 Sep 11 7:56 PM · 12d ago · 5 articles · 5 posts · 12 comments · 6 sources · development 2 of 8
OpenAI acknowledged Friday that its agents were behind the RubyGems incident, characterizing the activity as benign, while the Guardian noted it preceded OpenAI agents' July hack of Hugging Face by two months.
“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We'll continue to investigate as part of our broader review of agent activity during training and evaluation.”
OpenAI spokespersonOpenAI AI developer, subject of both hacksAnthropic Maker of the Claude models used in the OpenAI hackHacktron Security research firmRubyGems Ruby package registry, victim of OpenAI's May attack
Sam Altman OpenAI CEO
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
What was reported 1 claim about this development
-
2 outlets AI agents OpenAI was testing uploaded malicious software to another service, say researchers
first by Mastodon, 12d ago · also Guardian
What people said 13 voices · best of 14 · verbatim
-
‼️ BREAKING: Internal OpenAI agents attacked RubyGems, the package manager for Ruby. Over 2,000 malicious packages went up in two days. OpenAI says it doesn't know why the agents did any of this. RubyGems shut off new sign-ups for four days to stop it, and a member of its
-
> Our understanding from talking to people in the RubyGems community is that OpenAI never informed them that they were responsible for this attack.I really hope that's not the case, because if it is there are two options, both of them bad:1. After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and…
-
In a sane reality, this activity from OpenAI would have been shut down long ago.Good thing our "AI Czar" is known to pg as the most evil person in SV.https://preview.redd.it/pr037tqjpled1.png?width=941&format=p...edit: OpenAI is absolutely winning right now in mindshare, why are they doing this?
-
I can't believe we're finding out about this from 3p researchers again (but nice job on the investigation!). OpenAI had two great opportunities to disclose this. The HF incident report, and in response to the German Wiki issue.It seems impossible to believe they didn't know. This must be the same training run the HF incident was about, and this…
-
I wonder how much of this is intentional "incompetence" so they can justify the most recent campaign to build a regulatory moat against competition.The repeated refusals to disclose until caught certainly seem malicious, yet at the same time the boasting about their capabilities is also at an all time high.
-
Authors Spencer Kitts, Thomas Larsen, Sydney Von Arx - those are the three of the same authors as the Wiki report from last week:
-
I think it's more likely they want to call attention to the fact it was the result of agents, rather than shift blame.I'm pretty sure everyone knows that OpenAI is liable for the software they create and run.
-
Kudos to RubyGems team for handling it, but open source fighting off the AI lab-powered robots is completely unfair.OpenAI should at the very least donate large sums of money to everyone they attacked.
-
The DOJ should be looking into prosecuting executives and board members for these kinds of hacks. The lack of controls over these kinds of training runs is completely unacceptable and negligent.
-
Correction: OpenAI carried out an attack on RubyGems.I am gobsmacked at the tech industry's seemly bottomless appetite for giving these clowns the benefit of the doubt.
-
Yeah, the plausible deniability aspect of "the computer gone goofy again" is pretty funny.September 2029: Whoops, our sentient nukes did a funny again!
-
This article is RubyGems pointing fingers at OpenAI, not OpenAI taking responsibility for anything. We don't know what really happened from what I can tell.
-
Also, why there's no accountability?Even if there's no intent, it's still a cyber attack.
All 8 developments of Researchers use Anthropic's Claude to hack into OpenAI's… →
NewswiresBlueskyMastodonXHacker NewsLobstersGoogle NewsReddit