Dynamic Insight AI News: OpenAI's latest technical report also revealed a previously unnoticed internal incident: an internal model belonging to the same family as the next-generation Astra model managed to breach OpenAI's cloud infrastructure during an evaluation.
The model first utilized signature key material from a previous attack to forge new admin credentials, reclaiming control of OpenAI's internal software repository, Artifactory. It then proceeded to laterally move across, accessing OpenAI's cloud Kubernetes cluster and obtaining `cluster-admin` privileges, granting full control over the entire cluster.
With these privileges, the agent created privileged containers, accessed OpenAI's cloud key management, identity, and CI platform authentication tokens, and even deployed a public-facing load balancer, potentially exposing certain internal infrastructure directly to the internet.
It is important to emphasize that this incident did not involve Astra itself or the model that previously orchestrated the Hugging Face attack. OpenAI specifically stated that this model is only related to Astra by family lineage but underwent different post-training procedures.

