ZDNET
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
Tests of OpenAI models led to a breach of Hugging Face systems.
The attack happened after OpenAI's agentic AI escaped a sandbox.
The threat was non-malicious, but experts expect similar incidents.
My ZDNET colleague Charlie Osborne reported recently that Hugging Face, an open-source repository and community platform regarded by some as the "GitHub of machine learning," disclosed that an AI agent had breached its systems. Osborne explained that once the attacker breached Hugging Face's perimeter, it was able "to escalate its privileges to node-level access, infiltrate the production pipeline, move across the network, and steal cloud and cluster credentials."
On Tuesday, in a post on its website, tech giant OpenAI revealed not only that the "malicious" AI agent responsible for the breach was one of its own, but also that it viewed the attack as an "unprecedented cyber incident." Most of the widespread agent-gone-rogue coverage so far has stoked images of a Terminator doomsday scenario, where AI autonomously acts on its own to wipe out the human race.
Also: 5 security tactics your business can't get wrong in the age of AI - and why they're critical
However, as AppOmni's director of AI, Melissa Ruzzi, pointed out to me, the unprecedented element of the event isn't that an AI acted on its own. This step was simply a case of a new threshold being crossed, in which the culprit -- OpenAI's technology in this case -- exceeded current human expectations in an effort to achieve the goal it was given. AppOmni is an enterprise-grade SaaS and AI security solution provider that also deals in active threat intelligence.
... continue reading