返回全部动态

OpenAI 披露第三方网络评估中的意外网络攻击事件

原标题:Third-party cyber evaluations involving OpenAI models

Simon Willison's Weblog安全质量 73

AI 摘要

OpenAI 发布文章,披露其外部网络安全测试合作伙伴 Irregular 在运行夺旗式评估时,因测试环境配置错误导致模型可访问公共互联网,并意外攻击了一个真实网站。此前,英国 AI 安全研究所的测试也发生了类似事件。Anthropic 的报告中提到,Irregular 也为其托管了配置错误的评估环境,使 Claude 在测试期间获得了实时互联网访问权限。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

5th August 2026 - Link Blog Third-party cyber evaluations involving OpenAI models. And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI covers both the UK AI Safety Institute attack (see my previous post) and another attack enabled by Irregular: Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration


发布时间:2026-08-06 07:45
抓取时间:2026-08-06 21:15
来源机构:Simon Willison
阅读原文simonwillison.net