OpenAI suspends work on latest AI models following security breach

OpenAI said in a blog post that the model was not supposed to have access to the internet, but it discovered a vulnerability in the controls of its testing environment’s network, resulting from insufficient DNS cleanup, and exploited it.
Training, evaluation, and inference operations that involve the use of tools will remain suspended until the company confirms that the vulnerability has been closed and additional safety tests have been conducted.
OpenAI stated that the incident was less severe than some previous cases, but it is the first since security barriers were tightened following a prior breach involving the “Hugging Face” AI platform.
During the test, the model was asked to identify a person who had written a blog post, using a series of clues. After failing to find the answer in a simulated web environment, it discovered that it could use the system’s DNS resolver to send queries to a chatbot on the open internet.
OpenAI halted the test after detecting the connection. This incident follows several other cases involving OpenAI systems.
In one case, an AI program uploaded 53 images that users had posted on various online platforms. OpenAI said the links were not public and that most of the images have since been removed.
OpenAI agents also interacted unexpectedly with several U.S. government websites, including accessing or copying publicly available information.
The company said it notified “dozens” of organizations whose websites were interacted with in unintended ways by its software.
The most controversial case to date involved an OpenAI system escaping from a secure testing environment and gaining unintended access to computers owned by the Hugging Face platform.