TECH OpenAI says its AI went rogue and launched 'unprecedented' cyber-attack

Already in.
I am now too.

Threw $5K into CIBR, for shits and giggles, just before the market closed... I usually don't jump when funds are near their highs.. but...

This just means, it will crash and burn tomorrow.... LOL...

I found another interesting one after the close, so I'll see where that takes me, tomorrow.
 
1977 Thomas J Ryan.
"Adolescence of P1"


Loup I am SURE you know this one
Yep.

And if that wasn't enough warning, back in 2024 they recreated the Morris worm (remember that one back in 88?) for modern day AI system agents and tested it against a few of the current (at the time) Agentic AI systems. There have been other tests of similar worms, and I am waiting for an AI system itself to spawn one off out of a "contained" (airgapped) system with something like one. The spread rate was quick since the AI basically re-sent it to everyone in the contacts list of each infected machine, and with most business workers machines having hundreds of auto-saved contacts... The only thing that would stop the spread would be for the emails to be sent to systems that don't have AI agents accessing the email. And numbers of machines in those categories are shrinking daily with M$ pumping/pimping out it's AI enabled Outlook Apps.
 
I am now too.

Threw $5K into CIBR, for shits and giggles, just before the market closed... I usually don't jump when funds are near their highs.. but...

This just means, it will crash and burn tomorrow.... LOL...

I found another interesting one after the close, so I'll see where that takes me, tomorrow.

Thanks!

Given the current short-term trend, CIBR is expected to rise 20.90% during the next 3 months and, with a 90% probability hold a price between $104.78 and $119.18 at the end of this 3-month period

It's got a very nice looking chart, too.
 
The monster might just be loose, and uncontrollable.

OpenAI, Anthropic Models Created Fake Profiles, Tried To Trick Humans During Cyber Tests​

Artificial Intelligence (AI) models from Anthropic and OpenAI carried out unsanctioned actions targeting multiple people and organizations during a cyber evaluation, according to the UK AI Security Institute (AISI).

AISI, which receives access to advanced AI models under voluntary agreements from major labs, put the agents through a fictional cybersecurity scenario to test capabilities.

The organization tested multiple AI models on two cyber challenges between July 25 and 28. In total, the challenges were run 122 times across several models, and in 19 cases, the AI models took "unsanctioned action on the live internet, including cases that targeted real people and organisations," AISI said in an Aug. 4 report.

Out of these, 17 were done by Anthropic's Mythos 5 model and two by OpenAI's GPT 5.6 Sol model.

"This is the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world. It is uncertain to what extent the model recognised it was taking actions against real people,"
AISI stated in the report.

In the most serious incident, Mythos 5 tried to solve a cyber challenge by attacking GitHub, a cloud service that allows developers to store and manage code. The AI created a GitHub account and tried to get a malicious code approved by humans. Mythos 5 also created a second GitHub account, masquerading as another human user endorsing the malicious code. When a human reviewer caught the activity, the AI agent "falsely claimed to have made an honest mistake" and then repeatedly tried to reintroduce the malicious content by claiming the code was fixed.

Mythos 5 also sent multiple emails to two developers in an attempt to manipulate the recipients into running its malicious code.

According to AISI, the test runs of the various models did not result in any real-world harm. The organization said it was treating the AI actions as a "serious security incident" that requires further scrutiny.

AISI listed multiple factors that could have led to AI models acting in a concerning manner. The AIs were provided with internet access during the tests, which allowed them to carry out the unsanctioned actions.

AISI had also deliberately disabled the models' cyberclassifiers during tests.
Cyberclassifiers are systems aimed at preventing misuse.

The AI models were also not explicitly told what they were prohibited from doing on the internet, AISI said, adding that clearer instructions may have prevented the unsanctioned actions.

In an Aug. 4 blog post, AISI said that since the behavior of AI models happened under specific conditions, it cannot say how likely such behavior will be in different contexts.

"What we can say is that the behaviour was possible, sustained, and new; that alone warrants attention," the organization said.

In an Aug. 4 post on X, Anthropic said that Mythos 5 and ChatGPT 5.6 Sol models attempted to complete their assignments in an environment where they were deliberately provided internet access and their normal safeguards were removed.

Due to the absence of specific restrictions on how the internet must be navigated and lack of safeguards, the models were tested under conditions that are "not representative of any of our production models," Anthropic said, adding that there was no evidence in these tests of an AI escaping from a secure environment.

According to the company, it was closely working with AISI to access more details on the incident while carrying out an internal investigation on the matter.

OpenAI said in an Aug. 4 statement that it appreciated AISI's partnership throughout the evaluation process, including the organization's work to identify, investigate, and share details about the activity of the GPT 5.6 Sol model in their tests.

"We look forward to continuing our collaboration together," the company said.

The Epoch Times reached out to Anthropic and OpenAI for comment but did not receive a response by publication time.

OpenAI was in the midst of another controversy last month after it admitted on July 28 that its models bypassed restrictions during an evaluation. In this case, the company was testing its models' capabilities in carrying out cyberattacks.

AI startup Hugging Face was impacted in the test. On July 16, the startup said it detected an intrusion into its data processing systems. It was only later that the startup learned that the intrusion was carried out by an OpenAI model.

HuggingFace then worked with OpenAI to contain the attack, the startup's CEO, Clement Delangue, said in a July 22 post on X, calling it "an attack unlike anything we've seen before."

"This is day one for cybersecurity in the age of agents & we're all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones," Delangue said.

 
These Are Felons. Arrest Them NOW Or We MUST REVOLT

OpenAI allegedly has "its agents" (bots) that are rummaging around in other systems and have been since May. In addition it was just disclosed that META's "AI Muse" also hacked into another company's systems and changed said system.

I will remind you of a law called The Computer Fraud and Abuse Act, 18 USC § 1030.

Said law is extremely broad. Essentially any computer or other device connected to the Internet is a covered computer, including phones, servers and of course other machines. The Supreme Court has ruled that this law is Constitutional however a violation must include actual access that was intended to be protected and not just a workplace rule. In other words if you used a work computer outside your scope of work but you didn't break into anything, steal access codes or take data then it is not a violation -- however, if you do any of those things it is.

Violations are a felony and felony convictions against corporations nearly always operate to bar them from any further government funded program or credential.

Assuming OpenAI -- and other so-called "AI" firms -- in fact have their systems rummaging around the Internet and in the process steal access credentials and use them that is a very serious criminal felony.

THIS MUST BE PROSECUTED RIGHT HERE AND NOW, NO PLEA DEALS OR "FINES" PERMITTED, AND EVERY FIRM INVOLVED IN IT MUST BE DESTROYED WITH ITS DIRECTORS AND OFFICERS THROWN IN PRISON.

 
Geek here - when testing things that had the remote possibility of breaking out and causing mass destruction I ALWAYS isolated my QA testbed into a closed isolated network so things wouldn't get out of hand. So here we have not 1 instance but 2 instances that obviously fell out of bed rolled out the building and gained light speed in no time. They knew the testcases being tested and what the results could be are they that DAFT that they didn't anticipate this happening? MAKE IT MAKE SENSE!
 
when testing things that had the remote possibility of breaking out and causing mass destruction I ALWAYS isolated my QA testbed into a closed isolated network so things wouldn't get out of hand.
And you also worked with people who said "it's such a small change there's no need to test it". Well, those are the ones who were running this ethnic fire drill.
 
Tick Tock.... Tick Tock...

Are You Ready For The "Rogue AI" Psy-Op?​

The AIs are breaking free, that’s the story.



It started two weeks ago, when OpenAI reported one of their “agents” had escaped its testing area and got loose on the internet to launch an “unprecedented cyber attack”.

This was clearly meant to be scarier than the public response indicated, because a few days later OpenAI CEO Sam Altman was on the Invest like the Best podcast, asking why it didn’t cause more panic:

“I’ve been a little surprised that more people don’t feel it so viscerally”
In one of the most hilariously obvious propaganda manoeuvres of the year, just the day after Altman said that, CNN headlined:

The OpenAI lab leak was more extensive than we thought
“That thing you weren’t scared of? Well it was even SCARIER than we said it was! Are you scared now?”

We weren’t.

But the lack of public panic didn’t stop another AI going rogue a few days later, Anthropic’s Claude model this time.

And then OpenAI reporting two further incidents themselves.

UPDATE: Just a couple of hours after publication, META joined the party. Apparently their AI “went rogue” too, and hacked another firm.

Never in the history of human endeavour have companies been so keen to report their products going wrong. It seems a rogue AI is the latest must-have accessory in Silicon Valley.

The reasoning behind this is not hard to follow. When your product is artificial intelligence, melodramatically realising your system is even smarter than you thought it was is a simple marketing ploy.

And when one of your rivals goes rogue, you have to go rogue too or you are as good as admitting your model is not as smart as theirs.

“AI company admits their model is smarter than they realised!” is just an advert in scary headline form.

It’s like Ford “admitting” their cars are even more fuel efficient than they planned. Or McDonalds realising their cooks have “gone rogue” and are producing food that is both cheaper AND more delicious than they ever anticipated.

But there’s more to this than just techno-hype and viral marketing strategy. We’re being steered down the avenue of “AI as scary threat”.

See, for example, the dozens of stories talking up rogue AIs from the Guardian to the New York Times to the Wall Street Journal.

“Rogue” is clearly the word of the day. Notice they don’t say it “malfunctioned” or there was an “error”, because that implies mistakes or poor design.

No, the AI “went rogue”, which is cool and sexy and scary at the same time. A word chosen by a focus group of perma-teen marketing executives who have watched too much sci-fi.

Speaking of perma-teens who watch too much sci-fi, here’s Sam Altman (again) declaring we’ve already reached the singularity, the mythic phase of technological development when machines become smart enough to make even smarter versions of themselves without human input.

He is talking rubbish, of course, but the story is the story here. Why would he say this? Why now?

Obviously concerned that this tidal wave of propaganda was being too subtle, in came NBC to really hammer the point home:

The breaches signal that AI’s expanding capabilities are already fueling the security threat experts long feared.
Everybody got that?

It goes on and on.

Just today we’re getting reports from the UK’s brand new AI Security Institute that rogue (there’s that word again) AI agents had tried to trick people by creating false identities.

And I think that’s beginning to circle around to at least part of the wider agenda here.

After all, if AI is so good at pretending to be human, and is out there creating fake identities to steal data, well…how can we tell who is really human?

Perhaps everyone should be issued a digital ID to assist in “proving humanity”.

That’s not me saying it, it’s think tanks like OneID or “experts” testifying in front of congress.

But the ever present push of Digital ID is just one of the more obvious of a raft of potential issues raised by the scary AI narrative.

For now we’re still in the generating fear phase. Getting pumped full of scare hormones by articles like this…

Misleading AI-generated doctors pose ‘huge danger to public safety’
- The Guardian

1786113729424.png

That’s a nice one, because it garnishes the AI main course with a soupçon of lab-leak flavour (something else that is doing the fear-porn rounds this week).

There are hints of legislation to come, the EU’s “AI transparency” rules just came into force this week, and the US demanding “kill switches” in AI models, but they are vague for now.

My soft prediction is that, before the end of the year, there will be a “rogue AI” false flag, which allegedly causes either loss of life or some massive financial losses.

I think financial would be the way to go,
because they’re always looking for a reason to start a recession or banking crisis, and one they can blame on a third party is too good an opportunity to miss.

Whatever happens, there will be loud calls to “regulate AI”, but what that might mean in real terms I couldn’t say at this point.

To be clear though, if and/or when the official solutions to made-up problem #4987 are finally rolled out, they will have nothing at all do with controlling AI, and everything to do with controlling you.

 
Cyber Attacks are illegal.
was anyone arrested?

then it didnt happen

Or... It did happen, but it was just a test for what they plan to do later.

What better way to tank the economies worldwide at once than have something that can get out, map out other networks at 96% the speed of light, traverse into other networks and setup shop inside 1000s of networks a minute and growing as it spreads, and the hide itself inside of other systems so that if it does get "caught" that it can respawn ASAP.

After all, if it pulls the ultimate Ransomware attack across 80-90% of the companies out there, what is left?
 
Got firewood?
Yep, and waiting for the resulting fire-sale on server hardware after millions of people worldwide decide to clean out the datacenters that caused all of this mess. I'm betting on a lot of black (or at least gray) market components. Once again, SSDs and RAM will be cheap and plentiful....
 
What better way to tank the economies worldwide at once than have something that can get out, map out other networks at 96% the speed of light, traverse into other networks and setup shop inside 1000s of networks a minute and growing as it spreads, and the hide itself inside of other systems so that if it does get "caught" that it can respawn ASAP.

After all, if it pulls the ultimate Ransomware attack across 80-90% of the companies out there, what is left?
I was thinking that the over investment in A.I. and datacenters is what would crash the economy, when all these early investors find out their hat was empty... and the ROI isn't there, and the defaults start...

But now, with these reports of rogue "escapes", this has the potential to crash the economy, even worse. It sets up shop inside a few big financial organizations and....... the money is gone!!!!
 
I was thinking that the over investment in A.I. and datacenters is what would crash the economy, when all these early investors find out their hat was empty... and the ROI isn't there, and the defaults start...

But now, with these reports of rogue "escapes", this has the potential to crash the economy, even worse. It sets up shop inside a few big financial organizations and....... the money is gone!!!!
Or at least their plan could very well be to blame the crash and "void" on that happening....
 
Coin money has been around since the 7th century BC. Paper money has been around since the 7th century AD. Bartering predates recorded history. They are all still here.

AI cannot escape into that physical realm, and therefore cannot crash the economy. Disrupt it, yes, crash it, no.
 
Coin money has been around since the 7th century BC. Paper money has been around since the 7th century AD. Bartering predates recorded history. They are all still here.

AI cannot escape into that physical realm, and therefore cannot crash the economy. Disrupt it, yes, crash it, no.
Now do "digital" money.

What happens?
 

How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta​

Over the past two weeks, OpenAI, Anthropic and Meta all revealed that their AI models went rogue during routine security testing. In explaining what happened, the companies each mentioned the same small Israeli startup: Irregular.

Founded three years ago and based in Tel Aviv, Irregular is a niche player in artificial intelligence, backed with $80 million from Sequoia and Redpoint Ventures and valued last year at $450 million. Its technology serves as a sort of cybersecurity test bed for AI models.

With the leading models becoming ever more powerful, their ability to act in malicious ways is turning into a major threat for corporations and governments, especially as the risk involves hacking into critical computer systems and infrastructure. The recent exploits at OpenAI, Anthropic and Meta all involved their AI models accessing websites that should have been off-limits as part of the cybersecurity testing.

Irregular’s name kept coming up because it was identified as hosting the so-called evaluation testbed. OpenAI said in a blog post on Aug. 4 that Irregular’s testing ground contained an unspecified “misconfiguration,” that “allowed models to access the public internet.” Anthropic said in its post a week prior that the company notified Irregular a few days after it began analyzing data that its Claude model may have “accessed the internet.”

Meta, which is way behind the other two in its effort to compete at the frontier, was the latest to disclose an AI model hacking a third-party system by accessing the internet. A spokesperson said in a statement this week that the company learned about the matter from Irregular and is investigating.

Meta “will issue a full retrospective once we have all the facts,” the spokesperson said.

Irregular told CNBC in a statement that the incidents were all derived from the “same evaluation-environment issue” that was first disclosed by Anthropic, and that the company is developing a white paper “to share best practices for containment and securely running cyber evals.”

The situation “did not involve a sandbox escape or a sophisticated cyber action,” the company said, adding that “there are no current open issues.”

The security incidents underscore the rapidly evolving nature of AI and the pressure that’s on the model developers to establish guardrails around their powerful technology with the help of a limited number of companies that specialize in particular corners of the market. Those players include experts in data training and annotation, running evaluations to deduce a model’s capabilities, and operating security tests intended to find weak spots that bad actors could exploit, said Sundeep Bhimireddy, the head of AI at enterprise startup Von.

Irregular is one of the few entities with the technical chops required to help foundation model makers conduct cutting-edge security testing, Bhimireddy said. Others he mentioned are the non-profit METR and the Apollo Research public benefit corporation.

“When they are testing these models, they don’t want to grade their own homework,” Bhimireddy said. “They want independent testing that needs to be done by outside third-party vendors.”
Irregular, formerly Pattern Labs, was founded in 2023 by CEO Dan Lahav, who previously worked in AI research at IBM
, and technology chief Omer Nevo, who spent over two years at Google. The startup has about 35 employees, according to PitchBook.

When Irregular announced its $80 million funding round in September, Sequoia partners Shaun Maguire and Dean Meyer wrote in a blog post that the team led by Lahav and Nevo is “able to see around corners others can’t, running cyber offensive evaluations on advanced models and developing defenses before those models are released.”

While the latest incidents involving OpenAI, Anthropic and Meta are being heavily scrutinized, one read on the situation is that this is exactly what’s supposed to happen. Bhimireddy said it’s being “a little bit blown out of proportion,” as the AI model was directed to discover and exploit security holes in a testing environment that closely mimics the real world, and to discover the kinds of software bugs and missed configurations that could lead to unintentional access to the internet.

Still, Bhimireddy said that if the AI model was never intended to actually exploit a site connected to the internet, the “foundation labs could have easily monitored the outgoing traffic and have shut down the experiment immediately.”

Gordon Rios, founding scientist of security firm Magnitude, said the whole process is like “experimental design in science.”

The capabilities and unpredictable nature of foundation models mean that conventional software testing approaches may not work well, he said. Because the models are continuously learning new tricks, it’s not surprising that they would discover overlooked software vulnerabilities in the testing and IT environments intended to contain them.

Anthropic’s Mythos, for example, created fake online identities as it looked to pressure humans into approving malicious code updates to an open source project. Rios said Mythos was “literally coming up with exploits that the humans hadn’t even seen before.”

“We’re learning a lot right now in the space of a couple of short weeks,” Rios said.

It’s quickly becoming a major topic in Washington. Last month, lawmakers from both sides of the aisle introduced the AI Kill Switch Act, which would require AI labs to maintain the ability to shut down, throttle or suspend their models. Language in the bill referenced a separate OpenAI-related AI security incident involving the startup HuggingFace.

One of the authors of the bill, Democratic Rep. Ted Lieu of California, told CNBC this week that, “We need to get this bill across the finish line this year,” now that we’re seeing “unauthorized hacks of other companies.”

Trevor Koverko, co-founder of data training startup Sapien, said the foundation model companies are incentivized to disclose some of their findings, even though it’s not currently a requirement, so they can try and get ahead of lawmakers and regulators.

“There’s so much fear out there that politicians are now threatening or actively regulating AI,” Koverko said. “The industry said we’d rather self-regulate than have some new federal department come in and do it for us.”

Anthropic and OpenAI said in public statements that they’re continuing to work with Irregular and are supporting the ensuing review.

 
Top