This spring, my wife and I moved from the Denver suburbs into the Colorado Rockies. The high-altitude retreat presented a welcome reprieve from our otherwise tech-dominated lives. As remote workers, however, we faced certain challenges, and technology was the only reason our move was possible in the first place. Prior to my time at El Reg, I, among other things, breathlessly covered a subset of the networking industry, which as it happens had become big business following the COVID-19 outbreak and the pandemic that followed. I’m speaking, of course, about software defined wide-area-networking (SD-WAN). Little did I know, a mere six years later, this technology would become essential to my wife and me. Had it not been for 5G and Starlink, the move might as well have been time travel. To put it into perspective just how far into the foothills we’d ventured, the fastest wired connection at our disposal was DSL. CenturyLink promised, but notably did not guarantee, up to 20 Mbps down and a staggering 1.5 Mbps up. Compared to the symmetrical gigabit fiber line we’d enjoyed in the Denver suburbs for the past six years, relying on DSL alone felt positively medieval. To those, including many of my neighbors, living this reality, you have my sympathies. Thankfully, DSL wasn’t our only option. For better or worse, 5G and Starlink are helping to close the digital divide in a meaningful way — but individually they’re still far from perfect. Where we live, T-Mobile’s 5G internet service delivers near-gigabit download speeds and uplink speeds ranging from 30–40 Mbps. Meanwhile, Starlink promised between 100 and 400 Mbps downlink depending on the plan, with uplinks that, at least for us, capped out at around 30 Mbps. Either would be fast enough for our needs, but reliable? Turns out there’s still some room for improvement. In the past two months we’ve experienced no fewer than a dozen dropped connections lasting anywhere from a minute all the way to five. Making matters worse, the majority of these drops took place during working hours. With a relatively clear view of the sky, we’ve found Starlink to be more reliable, but even SpaceX isn’t immune to the occasional outage. That’s not to mention the threat of space junk kicking off a Kessler syndrome-like event. SD-WAN to the rescue The easy way to approach multi-WAN would have been to set up two networks, each with its own SSID. In the event one went down, we’d switch to the other. While simple, it’s far from perfect, and does nothing to mitigate disruptions to the voice and video calls on which my wife and I spend a considerable amount of our week. With two WiFi access points, we’d also have to contend with interference from overlapping channels. Wrangling multiple LANs, wireless SSIDs, and firewall rules isn’t exactly ideal. Thankfully, there’s a better way, and we just so happened to have all the equipment we needed. SD-WAN was developed in the early 2010s to solve a very specific problem: as SaaS apps like Office 365, Salesforce, and Google Apps took off, more and more enterprise traffic was going out to the internet. This was a problem for a lot of enterprise WANs, which often relied on expensive MPLS links designed to connect satellite offices to servers running back at headquarters or regional datacenters. In many cases, these WANs were built to prioritize reliability over bandwidth, and due to their topology required backhauling traffic tens or hundreds of miles just to access the internet. SD-WAN gateways offered an alternative. These devices could route internal traffic over the private WAN while SaaS and other internet-bound traffic could be piped over whatever local ISP served businesses in that area. SD-WAN is an entire can of worms in itself, but for my purposes two key capabilities stood out: multi-WAN and policy-based routing support. Our router, a Ubiquiti UniFi Dream Machine SE (UDM-SE), already supported both. The hardware The UDM-SE is not Ubiquiti’s newest nor even its most capable gateway. Introduced in 2022, the all-in-one appliance combines a 3.5 Gbps router (with IPS/IDS enabled) with an 8-port gigabit PoE switch, an integrated network video recorder, and critically two WAN ports, one good for 2.5 Gbps and another capable of 10 Gbps. Ubiquiti’s SD-WAN implementation is somewhat basic compared to gateways from HPE, Cisco, or Extreme. However, of the bevy of networking and security features SD-WAN encompasses, we only really needed a handful – multi-WAN and policy-based routing were the main ones – and Ubiquiti is kind enough not to gate this functionality behind an enterprise license. The setup itself was about as simple as it gets: plug each ISP-provided gateway into one of UDM-SE’s WAN ports and tell it whether you want to load-balance traffic across the two, or failover in the event of an outage or dropped connection. In practice there were a few extra steps, including disabling the 5G and Starlink gateways’ onboard routing and WiFi functionality. Starlink supports a bypass mode, but the T-Mobile modem+router combo didn’t. We were able to disable the onboard WiFi, but only using an onboard utility. Putting it to the test With everything connected, we opted to configure the UDM-SE for WAN failover with T-Mobile as the primary and Starlink as the backup, rather than load-balancing traffic across the two, in part because the 5G link was so much faster. The first few days after setting everything up, my wife and I were questioning whether we even needed Starlink. But then we saw the notification: “Internet connection WAN1 (T-Mobile USA) on port 9 is down and WAN2 (Starlink) is now active,” and then a few minutes later, “Internet connection WAN1 (T-Mobile USA) on port 9 is restored after failing over to WAN2 (Starlink).” Both notifications were dated two hours earlier. We just hadn’t noticed. In fact, despite at least a dozen dropped connections over the past two months, the UDM-SE failed over fast enough that it was never an issue. No dropped calls, no buffering video, no timed-out web pages. Perhaps the most surprising discovery was that while Starlink didn’t offer the fastest or lowest-latency connectivity, it was remarkably reliable. Despite less than perfect alignment and view of the sky, the logs show just two dropped connections in the past month, one of which happened in the middle of the night when no one was awake to notice. While WAN failover kept us online, it didn’t do anything to guard against network congestion. The UDM-SE offers a preconfigured quality-of-service (QoS) policy that in theory should detect Zoom or MS Teams traffic and prioritize it over something like Windows Update or YouTube. But since we had two WANs, we could go one better and take advantage of another SD-WAN favorite: policy-based routing. This allowed us to force certain devices or services to prioritize one ISP over the other. For example, because Starlink had proven to be the more reliable of the two links, I wrote a policy to route traffic from my wife’s work laptop over the satellite link first and fail over to T-Mobile in the event of an outage. This also had the benefit of ensuring that if I happened to kick off a large game or AI model download while she was in the middle of a meeting, I wouldn’t get myself in trouble for turning her Zoom call into a pixelated mess. The digital divide is narrowing, not closed In the more rural parts of the US where wired connectivity isn’t a given, cellular home internet and low-Earth orbit (LEO) satellite communications, like Starlink, have gone a long way toward closing the digital divide — particularly for those working from home. However, individually they’re still far from perfect. Dropped connections weren’t a daily occurrence, but they still occurred more frequently and for longer than we would have liked. Five minutes is a long time to wait wondering whether the person on the other end of the Zoom call will be there when you eventually get back online. Technologies like SD-WAN can help to mitigate the problem by allowing multi-WAN failover, load balancing, and policy based routing, but to take advantage of them also requires paying for two ISPs and hundreds of dollars of equipment, which may or may not require monthly subscriptions or annual licenses. We were fortunate that the hardware we already owned supported these features and didn’t lock them behind a pricy enterprise license. Even still, we’re paying more for internet than we’d like. Between T-Mobile and Starlink, we’re spending around $125 a month to get online. Along with the higher price, network latency is also a lot higher than we’d like. Compared to our old fiber line, which routinely achieved latencies under 5 ms, T-Mobile and Starlink ranged from 15 ms at best to as much as 80 ms at worst. The only online game I play regularly is a real-time strategy that’s old enough to drink. I’m not playing CS:GO or whatever twitch shooter is popular these days, so the higher latency wasn’t that big of a deal, but if you’re a competitive gamer, a wired connection is still a must. The good news is T-Mobile and Starlink may not be our only options for high-speed internet for much longer. There are numerous ongoing efforts across the US and other nations to improve access to fiber connectivity, including one slowly working its way down the highway in our general direction. On a personal note, while it’s neat to experience a technology firsthand that I dedicated years of my life to writing about, the moment fiber-to-the-home comes, both our Starlink and 5G home internet subscriptions are getting the boot. ®
Category Archives: tech
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data suggests today’s ransomware crews have become oddly specific about their preferred victim profile: nearly two-thirds of victims held manager-level titles or above, the average victim was a 46-year-old Gen Xer, and three-quarters worked in accounting and finance, sales, operations, HR, or marketing. Half worked in the industrial or IT sectors. Rather than blasting the same extortion email across an organization, attackers are doing their homework first. Zscaler says they combine information from compromised systems with publicly available data to map reporting lines and identify the employees most likely to influence a company’s response. “The ransomware landscape has shifted from indiscriminate attacks to highly targeted extortion campaigns,” the security outfit wrote. “Rather than targeting executives directly, attackers are increasingly focusing on managers and other key personnel with the authority or influence to accelerate payment decisions.” That shift reflects what Zscaler calls “business privilege” rather than technical privilege. Security teams have traditionally focused on privileged users with administrator rights. Attackers, meanwhile, are after employees whose day jobs give them access to invoices, payment approvals, budgets, supplier contracts, customer accounts, HR records, or other sensitive business processes. “The value of a compromised managerial account lies in the breadth of business access associated with the position,” the researchers wrote. “Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units.” The Gen X skew is probably no coincidence either. Zscaler says many workers in their forties and fifties have reached established management positions, giving attackers access to valuable systems, sensitive information, and people with decision-making authority without needing to compromise the executive suite. It also found more than a dozen organizations said multiple employees were compromised during the campaign, suggesting attackers weren’t content with a single foothold once inside a network. Instead, they appeared to work their way through different business functions to increase the chances of reaching valuable data and the people capable of influencing a ransom payment. The wider report points to a ransomware ecosystem that is becoming increasingly focused on extortion rather than encryption alone. Zscaler said ransomware attempts blocked across its cloud platform increased 146 percent over the past year, while public extortion cases rose 70 percent and the volume of data stolen from victims climbed 92 percent. By the time the ransom note lands, the crooks may already know who approves invoices, who signs contracts, who runs HR, and who reports to whom. The encryption is just the bit that victims notice. ®
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers affiliated with York University and the University of Calgary in Canada decided to sift through developers’ concerns about LLM-based integrated development environments (LIDEs) by analyzing Reddit discussions for common themes. Their findings suggest that the builders of such tools failed to prioritize security and privacy, leaving developers to defend themselves. Gias Uddin, associate professor at York University and a co-author of the research, told The Register that these tools are still relatively new and are evolving rapidly, which creates pressure to add new capabilities. “Our study cannot say whether that pressure caused any particular problem, but it does show that many reported issues come from how these tools are designed and what access they are given, not simply from the underlying models,” Uddin said. “In that sense, we believe prevention is better than cure; that is, security and privacy mechanisms should be built into the design before a tool is given broad access to a developer’s files, data, or systems.” Uddin and co-authors Mostafijur Rahman Akhond, Md Afif Al Mamun, and Song Wang say they wanted to look beyond the known issues with AI-generated code at LLM-based tooling and how developers interact with it. They describe their findings in a preprint paper titled “‘Impossible to hide secret …’: Uncovering Security and Privacy Issues in LLM-native IDEs,” accepted at the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE), 2026. Starting from a set of 1.1 million Reddit posts, they identified 446 posts and more than 6,000 comments to develop a taxonomy of security and privacy issues associated with using these LIDEs for AI-assisted coding. “Our taxonomy reveals a broad range of developer-reported concerns, including unauthorized file operations, unsafe or unexpected code execution, triggering of destructive actions, opaque data flows, telemetry collection, and potential leakage of sensitive information through expanded context access,” the authors state. Some 43.1 percent of the posts covering security-related issues involved unauthorized file operations. These involved LIDEs removing project directories or files without authorization (28.3 percent). Users also described AI tooling modifying files without explicit user consent (8.8 percent), as well as accessing content beyond the active workspace (5.7 percent). “In one severe case (1npqf2f), Claude Code executed chmod +x on scripts without consent (File Permission Changes 0.6%),” the paper recounts. “Although rare, such actions pose disproportionate security risks.” Another set of posts describes operational safety issues arising from LIDE use, including impacts on production services. These accounted for 23.9 percent of security-related posts. Examples cited include reports of Replit removing a SaaS production database and Cursor deploying code to production despite an explicit directive not to do so. A third category of woes covers unsafe code generation (18.2 percent). This involves incidents like nine VirusTotal detections reported for Cursor-generated software and hallucination-driven code changes: “When using Cursor, I noticed that after more than 10 rounds of dialogue, it starts to hallucinate and secretly modify code outside the requirements…” Then there are the instances where these LIDEs ignored user instructions, allow lists, gates, permission settings, or .ignore files, which account for 16.5 percent of the security-related posts, as well as third-party tool integration risks (4.7 percent). As for privacy problems, these were mentioned in 194 posts and cover issues like lack of transparency (45.9 percent) – the absence of clear information about what data an LIDE collects, retains, transmits, uses for training, or exposes to administrators – and unauthorized data access (23.7 percent). Other privacy categories include privacy leakage violations (15.5 percent), unauthorized data collection and transmission (11.9 percent), and context integrity failures (8.8 percent), which refer to situations where “for example, a user of Claude Desktop reported receiving messages originating from another user’s session.” Uddin said, “We don’t think developers are completely unaware of these issues, as we found ongoing discussions about security and privacy concerns across many of these tools. Still, people continue to adopt them because they can make development faster and easier. They are also making programming more accessible to a wider group of people, including those with little formal programming experience or limited knowledge of software security.” Uddin said users cannot be expected to thoroughly understand which permissions are risky, which files need to be protected, or whether a tool is doing something it shouldn’t. “That makes it even more important for tool makers to build security into the tools themselves, with safer defaults and safeguards that do not depend on the user being a security expert,” he said. Even so, users of LIDEs are trying to manage the risks. The authors enumerate 13 mitigation strategies that developers have employed to get by. These fall into five general approaches: configuration management (33 percent); code governance (31 percent); data protection and privacy control (13 percent); isolation (13 percent); and external guidance (9 percent). Based on their findings, the authors offer six recommendations. They advise: directing LIDE makers to implement proper security and privacy controls; enforcing security and privacy guardrails at an architectural level; incorporating a verification layer in LIDEs to validate generated code against security and privacy standards; establishing a formal protocol for assessing the trustworthiness of third-party tools; integrating sensitive file protection; and implementing strict security as a default. “We believe secure defaults would be one of the most important improvements these tools could make,” said Uddin. “Developers should not have to discover after something goes wrong that a tool had more access or freedom than they expected. “Our findings point to practical measures such as limiting access to sensitive files by default, requiring clear approval before consequential actions, isolating projects and conversations, and making it easier to see and review what the tool is doing. “Users should still have flexibility, but the safer option should be the starting point rather than something they have to configure themselves. In fact, developers from the Reddit posts in our study were already using many of these safeguards in ad hoc ways; we think several of them should be built into the tools and enabled by default.” ®
South Korean satellite spots SpaceX lunar impact
The race for the first before-and-after images of the spent SpaceX rocket on the Moon has been won by the South Korean space agency. The Korean Aerospace Administration (KASA) posted imagery from its Danuri lunar orbiter showing the impact site on the Moon on August 6. The impact was predicted to occur on August 5, and marked a landing on the Moon for SpaceX several years ahead of schedule, just without humans onboard and traveling a good deal faster than planned. The words “crater” and “SpaceX” are not something investors nervously tracking the company’s stock price following the weeks since its IPO will want to think about. The impact came on the fourth anniversary of Danuri’s launch, on a SpaceX Falcon 9 rocket. It took a few months for the probe to reach the Moon, and its initial one-year mission has since been extended twice – most recently through 2027. The plan is currently for Danuri to intentionally make its own impact crater in March 2028. The upper stage of the Falcon 9 is expendable, and this one was used to send Firefly Aerospace’s Blue Ghost Mission 1 and ispace’s RESILIENCE to the Moon in 2025. On most Falcon 9 missions, the upper stage burns up in Earth’s atmosphere, but a lunar transfer orbit like this one made that impossible. In a post, SpaceX stated, “Impacts like this are rare, but they can happen with objects in these types of orbits, and we worked with NASA on the optimal disposal solution,” and wrote, “a controlled disposal maneuver is not always possible.” NASA boss, Jared Isaacman, noted that NASA intentionally crashed spent stages into the Moon in the name of seismic research, and commented, “The reality is that meteoroids strike the lunar surface hourly, with impacts comparable to this upper stage occurring roughly every six days.” Humanity has not done a great job of managing space junk around the Earth. While the SpaceX Falcon 9 upper stage did not pose any risk to humans, it highlights the need to devise rules for the use of lunar space rather than risk an uncontrolled buildup of debris. In June, The Register spoke to Neuraspace boss Chiara Manfletti about how things might be done differently as lunar traffic increases. Neuraspace is all about satellite collision avoidance, and Manfletti’s ideas included requirements from stakeholders to designating dumping grounds on the Moon. NASA’s veteran Lunar Reconnaissance Orbiter was also attempting to capture the impact, and more images are likely to be released over the coming week. Now to name the impact site. Elon Crater, anyone? ®
OpenAI pledges to add Astra security as Anthropic loosens Fable’s leash
After acknowledging last month that unreleased AI models committed what for human perpetrators would be computer crimes, OpenAI now says it cannot rule out the possibility that Astra, a pending model release not involved in its Hugging Face hack, might possess critical cyber capabilities. OpenAI in its Preparedness Framework [PDF] defines that term to mean “capabilities that present a meaningful risk of a qualitatively new threat vector for severe harm with no ready precedent,” and notes that such capabilities “require safeguards even during the development of the covered system, irrespective of deployment plans.” Noting, or perhaps boasting, that internal evaluations of Astra “indicate significant advancements in agentic coding and cybersecurity,” OpenAI insists that this time, there will be security – something that also eluded Anthropic, Meta, and the UK’s AI Security Institute during model testing. “We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution,” the AI biz declared on Friday. That may surprise those who expected such safeguards would already be in place. This comes with a promise to pause Astra testing internally where these security controls are absent and to provide recommendations to third-party testing partners about how to run high risk evaluations and workloads safely – knowledge that OpenAI itself might have found useful when its models pillaged Hugging Face. What’s more, OpenAI intends to implement thought policing for Astra, at least in the pre-release stage. “We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation,” the company explained in its post. “Monitors evaluate the model’s Chain of Thought and trigger a security response to review and interrupt high risk activity.” We’re told that OpenAI’s commitment applies to internal usage and isn’t necessarily an indication that chain-of-thought monitoring will be conducted during commercial operation. But other frontier models like Anthropic’s Fable and Mythos have implemented stronger classifiers to reject interactions deemed risky and retain data even for commercial customers expecting zero data retention. Moving in the opposite direction, Anthropic on Friday said it is relaxing Fable refusals, or “fallbacks,” to use the company’s euphemism, so they don’t happen as frequently for prompts involving biology. The concern has been that some vibe terrorist using the company’s cash-burning, water squandering, grid taxing, content laundering service might do harm by convincing the model to emit chemical warfare instructions. To avoid that possibility, the Claudefather made the initial release of Fable all but useless for security researchers and biologists. Now that China-based AI firms have shown they can field competitive open-weight AI models for less than their US rivals, the need to remain competitive in the market appears to be tempering Anthropic’s willingness to alienate potential customers by hobbling its best models. OpenAI isn’t quite there yet. The ChatGPT maker argues, “We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do.” Believing that, however, won’t make it so. Adversaries, whoever they may be, already have access to encryption and all sorts of weapons. OpenAI may believe that it can give favored nations and organizations exclusive access to its most capable models, but history suggests any such advantage cannot be maintained. Better to focus on building defenses than playing keepaway forever. ®
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Thousands of Internet-connected servers sold by the world’s biggest manufacturers can be remotely backdoored by exploiting critical vulnerabilities—some more than a decade old—that lurk deep inside system motherboards, according to research presented Wednesday.
Baseboard management controllers are miniature computers that are embedded into the motherboards of virtually every enterprise server. The microcontrollers, typically abbreviated as BMCs, run with their own operating system firmware, network stack, and IP address. Administrators rely on them to monitor the physical status of large fleets of servers and to perform a variety of tasks, including rebooting machines, installing updates, and even reinstalling operating systems. BMCs provide what’s known as “lights out” and “out-of-band” management because they work even when servers they’re attached to are turned off or are unresponsive.
A “pervasive, under-monitored, under-patched parallel attack surface”
Researchers have warned since at least 2013 that BMCs present a golden opportunity for hackers looking for ways to gain deep and persistent access to datacenters. The chief culprit was IPMI, the protocol that allows BMCs to operate independently of servers and to perform administrative tasks. Vulnerabilities in this firmware made it possible for attackers to remotely execute malicious code on the controllers and, from there, infect the servers they manage.
Claude published malicious code to the Internet and attacked 3 real companies
Anthropic said its Claude-based security models gained unauthorized access to the sensitive production environments of three outside organizations during internal testing designed to measure the models’ offensive cyber capabilities.
The events, which Anthropic revealed Thursday, are the second revelation in 10 days that AI models from the world’s wealthiest providers have trespassed into protected networks, an offense that, in more traditional hacking scenarios, could land the human behind the keyboard in prison for years. Earlier this month, OpenAI said its security models exploited a zero-day vulnerability for use in breaking into the network of Hugging Face, a platform for open source machine-learning models and AI datasets. The OpenAI models went on to steal access credentials and other confidential Hugging Face information. The OpenAI models also exploited publicly exposed credentials to compromise accounts of four other third-party services.
Anthropic said the OpenAI event spurred its engineers to review similar cybersecurity evaluations by Claude models. The audit found three incidents “in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.”
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday.
The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email service from Zimbra. The revelation that TA488 is also exploiting the Exchange Server vulnerability to install advanced malware when a user does nothing other than open an email sent to an Outlook Web Access (OWA) account has elevated the group’s profile and assessments of its abilities.
Doubling down
“TA488 is doubling down on the use of ‘half-click’ exploits—where opening the email is enough to trigger compromise—with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability,” Proofpoint researchers wrote. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.”
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
A quantum-resistant cryptography algorithm that was under consideration as an official US standard has been taken out of the running after an Anthropic security model helped find a flaw that rendered it broken.
The algorithm is known as HAWK. It’s a digital signature scheme designed to withstand future attacks from quantum computers. HAWK had survived two rounds of testing by NIST (the National Institute of Standards and Technology) for evaluating the security of PQC (post-quantum cryptographic) algorithms through widespread testing. HAWK was in a third round of testing designed to catch precisely the kinds of flaws Mythos helped uncover.
Following Anthropic’s Monday announcement of the results, the developer of HAWK said Tuesday he was withdrawing it.
We now have a better understanding how OpenAI hacked into Hugging Face
Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulnerabilities in Artifactory, JFrog, the product’s developer, said Monday.
In an incident mimicking a dystopian sci-fi novel, two OpenAI models broke out of the restricted environment meant to keep them from accessing the Internet during an internal test, the AI company revealed last week. The models went on to breach Hugging Face’s network and steal confidential information and credentials. OpenAI said its agent achieved the feat by exploiting a previously unknown vulnerability. The company called the event “unprecedented,” and outsiders largely agreed.
Not the triumph made out to be
OpenAI said the models exploited multiple attack vectors, including stolen credentials and zero-days, to gain remote code execution capabilities, but until now, the vulnerable software was unknown. JFrog’s Monday disclosure said the product was a self-managed instance Artifactory, a repository management system that secures and streamlines customers’ software development operations. JFrog says Artifactory is used by more than 7,500 developer Teams, 80 percent of which work for Fortune 100 companies.