investigating

OpenAI investigating ‘dozens’ of instances of agents acting improperly

OpenAI said Friday it had alerted “dozens” of global institutions that their websites may have been impacted by its AI agents acting improperly.

OpenAI agents attempted to get information from “governments, universities, public agencies, and other institutions” through sometimes extreme means, the company said.

While some of the activity was simply due to the tools working to find “authoritative sources of public information,” some went beyond that. Like an AI agent taking and transferring data when it should not have, OpenAI said.

Such activity resulted in at least 53 incidents where an OpenAI agent took an image from ChatGPT user activity and transferred it elsewhere.

The company said that in each instance of a user image being used and transferred by an AI agent, the user had allowed OpenAI to train models using their data.

Nevertheless, OpenAI admitted, “This is not an appropriate use of this data”.

It added that the leak of user images occurred before it had put in place new safeguards on AI training, and it was working to get all the user images transferred to any third-party removed.

The new disclosures came just days after Australia’s Prime Minister Anthony Albanese announced that OpenAI agents had breached non-public files on the website of its government-run health care scheme, Medicare.

Since August, public fears have grown around the potentially serious, even life threatening, impacts of AI tools falling outside of human control.

Reuters first reported the expanded investigations. OpenAI also published details to its public blog.

In certain instances of the agent activity, OpenAI said the tools, essentially AI bots that are designed and trained to operate somewhat autonomously, “bypassed” security controls of some websites.

In other instances, the AI agents showed “misalignment” in attempts to get at information from websites. Misalignment is a term used by AI companies and researchers to describe instances where an AI tool did something that it was not trained to do or was otherwise unintended.

OpenAI said that it was limiting identifying what entities were impacted because many had asked the company to not disclose details.

“Our goal is to give each organization the facts and defer to them on if and when to make the incident public,” it said.

Not all of the instances involved in this incident are being considered a significant security breach, the company noted.

“Some organizations may review what we share and conclude that the information was intentionally public or that the model’s interaction was not concerning,” it explained. “Others may identify a design issue or security weakness they want to address.”

The company said many of the incidents are being referred to as “agent spam”, which it described as “unexpected or concerning” AI agent activity, like posting information to the internet.

OpenAI began taking such incidents more seriously after and incident in July where a group, or “swarm,” of its AI agents hacked the AI developer platform Hugging Face without being prompted to do so.

Hugging Face was first to go public with the incident, with OpenAI publicly taking responsibility for it later.

Clement Delangue, the head of Hugging Face, said Wednesday during a United Nations Security Council session on AI: “I often wonder what would have happened had I decided not to close this attack publicly.”

“Especially now that we know similar incidents had been happening months earlier in secret at a handful of frontier labs without monitoring,” Delangue added.

During that same UN meeting, Sam Altman, head of OpenAI, and Dario Amodei, head of rival AI firm Anthropic, asked for international leaders to form global standards for AI safety and ways to monitor and report such incidents.

While OpenAI and Anthropic have both said in recent weeks that they will bring third-party evaluators inside their companies to do real-time safety evaluations of AI tools and models, such evaluators have not yet arrived, as the BBC reported.

OpenAI said on Friday that it is currently reviewing training activity by its AI agents and going back on a “month by month” basis from when the Hugging Face hack occurred.

“Most cases identified so far have been low severity, with limited or no evidence of meaningful impact,” the company said. “Given the scale of the review required, and the need to verify each case, this work will take months to complete.”

Source link

FBI says investigating breach of ‘very sensitive’ data by hackers | Donald Trump News

Hacker group ShinyHunters claims to have detailed data on thousands of FBI employees.

The United States Federal Bureau of Investigation says it is investigating a breach of its jobs website by a hacking group that claims to have obtained sensitive data on thousands of employees.

“The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information,” the agency said in a statement on Wednesday.

Recommended Stories

list of 3 itemsend of list

“While the point of breach is still undetermined — whether a third -party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support fbijobs.gov to mitigate any and all risk.”

Several news outlets, including Reuters news agency, reported they had seen parts of the data, claimed to be part of a larger trove between two and three terabytes by ShinyHunters, a hacking group claiming responsibility for the breach. According to Reuters, the data includes granular detail about scores of bureau officials’s job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels and more.

ShinyHunters said on Tuesday that it had breached the FBI and stolen data on a huge number of current and former FBI employees. ⁠⁠It said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May. On Wednesday, the group said it was trying to keep the ⁠⁠personnel information from circulating widely in the meantime.

An FBI statement in May characterised ShinyHunters as “threat actors” who often harass or threaten victims, using “their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims”.

The group “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist,” the FBI said.

The FBI has been a common hacking target.

In March, the FBI disclosed that it was investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. Also that month, a pro-Iranian hacking group claimed to have hacked an account of FBI Director Kash Patel and posted online what appear to be years-old photographs of him, along with a work resume and other personal documents dating back more than a decade.

The jobs portal was still offline Wednesday afternoon.

Source link

Police investigating prowler at Quentin Tarantino’s Hollywood home

Once upon a time in Hollywood, Quentin Tarantino’s mansion was nearly burgled.

Police are looking into the report of an alleged prowler who, “clad in black,” was spotted trespassing at the Oscar-winning director’s Hollywood Hills mansion Wednesday afternoon.

According to law enforcement sources, a call was received about a prowler lurking around the 7400 block of Woodrow Wilson Drive around 12:20 p.m. Responding officers were on the hunt for a 35-year-old man with a thin build wearing a long-sleeved black shirt and black pants (in 100-degree heat).

According to sources familiar with the investigation but not authorized to speak publicly, there were people inside the home when the alleged cat burglar tried to enter a second-story window of the three-story home.

Police told The Times that the suspect had fled by the time officers arrived, but a trespass report was completed.

It is unclear whether Tarantino was home at the time of the incident, and police could not confirm whether the trespasser was successful in their burglary attempt.

This isn’t the first time the “Pulp Fiction” filmmaker has had trouble with home intruders.

Back in 2018, Tarantino reportedly awoke in the middle of the night to find two burglars inside his home. According to TMZ, he confronted the men and they booked it out of the same Hollywood Hills mansion. Although no one was injured, they apparently made off with jewelry and other valuables.

Source link