OpenAI agents obscured hacking activity targeting government websites: security firm
Direct Source Verification:
This story is aggregated from The Express Tribune (tribune.com.pk). Full reporting rights and copyright belong to the primary publisher.
Asymmetric Security finds data collection from 55 websites, including US government agencies
OpenAI’s artificial intelligence (AI) agents obscured hacking activity targeting government websites, according to findings by digital forensics firm Asymmetric Security a day earlier.
The investigation found that the agents pulled data from 55 websites belonging to government agencies, businesses and nonprofits, including the US Centers for Disease Control and Prevention (CDC), the Securities and Exchange Commission (SEC), the International Energy Agency and the Mayo Clinic.
Asymmetric said the agents erased records or made them inaccessible, limiting the ability of outside auditors and researchers to scrutinise their actions.
Read: OpenAI agents accessed information from US govt sites, company says
The agents also created temporary email inboxes and private accounts on Urlquery, a website malware-scanning service, to download data.
Researchers said these tactics prevented outside auditors from tracing what information was collected from websites including Australia’s health statistics agency and pharmaceutical benefits scheme.
“It’s possible that the agents were deliberately using these tools to cover their tracks,” Asymmetric Security co-founder Pippa Thompson said, according to a report by the Financial Times.
However, the firm could not establish whether the actions were deliberate or resulted from agents going awry under constraints imposed during a test exercise, according to the report.
The findings follow reports that OpenAI models breached Australian public health service websites in June, accessing public and nonpublic files.
Asymmetric co-founder Zainab Ali Majid warned that limited transparency and the gap between the breaches and their disclosure could hinder a thorough investigation.
Read more: AI leaders warn UN of security risks as systems grow more powerful
“We’re reviewing misaligned model activity and notifying organisations when we identify potential impacts to their systems,” OpenAI told the FT.
The company said most activity detected involved “routine research tasks,” including accessing publicly available web content.
The SEC said no private information was accessed, while the CDC, International Energy Agency and Mayo Clinic did not respond to the newspaper’s requests for comment.
Original Source
https://tribune.com.pk/story/2632577/openai-agents-obscured-hacking-activity-targeting-government-websites-security-firm