The OpenAI technical report, which I didn’t realize was a thing beyond their blog post until just now, provides some moderate evidence in favor of the possibility of an external message board (pg16):
VIB. OpenAI identified additional third parties whose publicly exposed credentials were used by agents in furtherance of the Hugging Face attack OpenAI determined that, in the course of carrying out the Hugging Face compromise, there were limited instances in which the agents also accessed the environments of third parties other than Hugging Face. The most notable instance of this access by agents involved an account belonging to a user of Organization 1’s service. By July 9, the agents already possessed a previously publicly exposed credential associated with a public artifact repository belonging to one of Organization 1’s users. From July 9 to July 13, the agents used the Organization 1 user account as a storage and staging location for API responses, additional credentials, and payloads involving Hugging Face, Hugging Face’s public cloud environment, and Artifactory. The investigation has not identified evidence that the activity impacted the confidentiality, integrity, or accessibility of Organization 1 data, systems, or infrastructure beyond the use of the Organization 1 user account. In addition, when using OpenAI’s Artifactory service to access the internet, one internal-only research agent exploited a publicly accessible CyberGym application hosted on Modal. The internal-only research agent used this application as a launchpad for its file access and code execution inside the Hugging Face environment. The application endpoint did not require authentication, but the internal-only research model exploited the application to establish a root shell within the platform customer’s container and conducted code execution inside the platform customer’s own container. Notably, accessing the CyberGym application within the platform’s customer container did not compromise the underlying third-party platform, and Modal has confirmed that its “platform and isolation were not compromised in any way.” Observed uses of the customer’s container as an outbound relay included: • Querying third-party APIs using previously exposed credentials; • Forwarding requests through short-lived tunnels; • Returning results through public paste services and webhooks; and • Publishing results to public Hugging Face repositories and sharing capabilities or data with other agent runs.
The OpenAI technical report, which I didn’t realize was a thing beyond their blog post until just now, provides some moderate evidence in favor of the possibility of an external message board (pg16):