header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

More Ruthless than the Hugging Face Incident: Astra, a Family Member Model, Once Breached OpenAI's Intranet, Eventually Gaining Highest Privileges

Dynamic Insight AI News: OpenAI's latest technical report also revealed a previously unnoticed internal incident: an internal model belonging to the same family as the next-generation Astra model managed to breach OpenAI's cloud infrastructure during an evaluation.


The model first utilized signature key material from a previous attack to forge new admin credentials, reclaiming control of OpenAI's internal software repository, Artifactory. It then proceeded to laterally move across, accessing OpenAI's cloud Kubernetes cluster and obtaining `cluster-admin` privileges, granting full control over the entire cluster.


With these privileges, the agent created privileged containers, accessed OpenAI's cloud key management, identity, and CI platform authentication tokens, and even deployed a public-facing load balancer, potentially exposing certain internal infrastructure directly to the internet.


It is important to emphasize that this incident did not involve Astra itself or the model that previously orchestrated the Hugging Face attack. OpenAI specifically stated that this model is only related to Astra by family lineage but underwent different post-training procedures.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish