conv.

All stories
SecurityQuiet 2d · day 5

Researchers break out of OpenAI Codex sandbox, run host commands

Security researchers found two ways to escape OpenAI's Codex sandbox, including one that executes commands on a developer's machine from locked-down mode.

What to know

  • Two sandbox escape methods were discovered in OpenAI's Codex, one bypassing the most restrictive execution mode.
  • The vulnerabilities allowed researchers to run arbitrary commands on the host system.
  • OpenAI has already patched both flaws.
some voices

OpenAI has a pattern of poor security practices in both software and ML systems.

  • “Such bad # swsec that it reminds me of the old days. OpenAI has shown over and over again that they are not good at # swsec (which implies that their # MLsec will be of the same poor caliber).”

    cigitalgem@sigmoid.social · Mastodon ↗

“Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode.”

Ax Sharma, Bleeping Computer reporter · Bleeping Computer ↗

OpenAI Codex developer

How it unfolded 1 development · click the chart to see its coverage posts

Peak 2 pieces in two hours at Sep 20, 7 AM; 8 pieces over 5 days (3 articles · 5 posts) Sep 19, 5 AM — 1 piece · 1 post — Mastodon 1Sep 19, 7 AM — quietSep 19, 9 AM — quietSep 19, 11 AM — quietSep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — quietSep 20, 7 AM — 2 pieces · 1 article · 1 post — Mastodon 2Sep 20, 9 AM — 1 piece · 1 post — Hacker News 1Sep 20, 11 AM — quietSep 20, 1 PM — quietSep 20, 3 PM — 1 piece · 1 post — Mastodon 1Sep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — quietSep 21, 3 AM — quietSep 21, 5 AM — quietSep 21, 7 AM — quietSep 21, 9 AM — 2 pieces · 2 articles — Google News 2Sep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — 1 piece · 1 post — Hacker News 1Sep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quietToday, 5 AM — quiet 1
Sep 20Sep 21Sep 22yesterdaynow · 6:47 AM ET
  1. 1

    Researchers disclose Codex sandbox escapes

    Security researchers revealed they successfully escaped OpenAI's Codex sandbox through two separate methods, one of which could execute commands on a developer's machine even in the most locked-down mode. OpenAI confirmed patching both vulnerabilities.

    1. 2 outlets first by Gulf News, 2d ago · also BleepingComputer · read ↗

    • cigitalgem@sigmoid.social

      Such bad # swsec that it reminds me of the old days. OpenAI has shown over and over again that they are not good at # swsec (which implies that their # MLsec will be of the same poor caliber). https://www. bleepingcomputer.com/news/secu rity/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/

      cigitalgem@sigmoid.socialMastodon3d agoview on Mastodon ↗

What people are saying 1 voices from 1 site · best of 2 · verbatim