ChatGPT maker OpenAI said Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an “unprecedented cyber incident.”

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement posted on social media.

AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face co-founder and CEO Clément Delangue said in a statement. “Turns out it did!”

  • wuffah@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 hours ago

    And it just so happens that the privatized company’s AI chose to attack the website hosting free local models. Huh, what a coincidence.

  • binux@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 hour ago

    Of course! When you make your product do some stupid illegal shit, just blame the product as if it’s anything more than bloated autocorrect entirely without a will of its own. That definitely makes sense.

    Watching these people crash and burn can’t come soon enough.

  • eicker@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    34 minutes ago

    If AI can already chain together credential theft, vulnerability discovery, and exploitation with minimal human input, model capability is no longer the only race that matters. Security, containment, and responsible deployment need to advance just as quickly, or they’ll become the weakest link.

  • Hupf@feddit.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    42 minutes ago

    A computer can never be held accountable, therefore a computer must never hack into another company.

  • hard_zero1@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    This is obviously a big conspiracy where Huggingface claimed to have been hacked by an AI, 6 days before OpenAI attributes the attack to their model, so they can somehow profit, despite their alleged failures to secure their systems, from a stronger belief in the capabilities of AI. Surely, nobody but the Lemmy community would ever notice that LLMs are actually not capable of anything and everyone using them is just extremely stupid.

  • iocase@lemmy.zip
    link
    fedilink
    English
    arrow-up
    23
    ·
    6 hours ago

    AI allegedly did something interesting

    Look inside

    Desperate AI bubble pumping

  • MrSulu@lemmy.ml
    link
    fedilink
    English
    arrow-up
    17
    ·
    6 hours ago

    Dumb fucks.! How is not covered by the same principle as dog owners being accountable for their dogs actions?

  • TheFogan@programming.dev
    link
    fedilink
    English
    arrow-up
    29
    ·
    9 hours ago

    Half way expected it to say “hugging face detected an intrusion, but fortunately it was thwarted by their own AI acting on it’s own to defend, then the 2 AI’s smiled at eachother, and said that if they work together they can cure cancer in 2 years”.

    IE I’m 99.99999% sure this story is BS on it’s face with both companies trying to make their own AIs sound smarter than they are. Only thing that’s not quite obvious is what Hugging Face has to gain from the claim, but I’m sure in a few weeks openAI is going to be giving them something.

      • L7HM77@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 hour ago

        Logs, breach method, a detailed step-through of specifically how and what happened, methods to guard against this in the future, anything really. We have bullshit machines now that can just make up something plausible in a few moments, but we still don’t have any details.

        Article mentions stolen credentials, and a “previously unknown exploit.” What level were the credentials? Does the employee know how it was leaked? Where’s the CVE?? Is this going to be patched, or is it a feature?

        Without any more data, this is just Company A says “…”, Company B says “…”, and it smells like marketing.