OpenAI has confirmed that state-affiliated bad actors are using the company's tech for malicious purposes, a validation of what many have feared since the company's rise to prominence in the generative AI race.
The discovery comes as part of a collaboration with Microsoft Threat Intelligence, a community of thousands of security experts, researchers, and threat hunters that analyze and detect cyber threats.
Using the network's intelligence gathering, OpenAI discovered at least five confirmed state-affiliated actors that were using OpenAI services for querying open-source information, translating, finding coding errors, and running basic coding tasks, the company explained. The actors included two China-affiliated actors known as Charcoal Typhoon and Salmon Typhoon; an Iran-affiliated actor known as Crimson Sandstorm; a North Korea-affiliated actor known as Emerald Sleet; and a Russia-affiliated actor known as Forest Blizzard.
SEE ALSO: Encryption backdoors violate human rights, EU court rulesThe accounts were said to be relying on OpenAI's services to bolster potential cyber attacks, but Microsoft did not detect any significant uses of the most-highly monitored LLMs.
"These include reconnaissance, such as learning about potential victims’ industries, locations, and relationships; help with coding, including improving things like software scripts and malware development; and assistance with learning and using native languages," Microsoft explained. "Language support is a natural feature of LLMs and is attractive for threat actors with continuous focus on social engineering and other techniques relying on false, deceptive communications tailored to their targets’ jobs, professional networks, and other relationships."
Microsoft distinguished this announcement as an early-detection effort, intended to expose "early-stage, incremental moves that we observe well-known threat actors attempting."
The collaboration aligns with recent moves from the White House to require safety testing and government supervision for AI systems that could impacts national and economic security, public health, and general safety. "While attackers will remain interested in AI and probe technologies’ current capabilities and security controls, it’s important to keep these risks in context. As always, hygiene practices such as multifactor authentication (MFA) and Zero Trustdefenses are essential because attackers may use AI-based tools to improve their existing cyberattacks that rely on social engineering and finding unsecured devices and accounts."
While OpenAI admits that its current models are limited in their ability to detect cyber attacks, the company committed to future security investments, including:
Investments in technology and teams, including its Intelligence and Investigations and Safety, Security, and Integrity teams, to detect threats.
Collaborations with industry partners and other stakeholders to exchange information about malicious uses.
Continued public reporting of security threats and solutions.
"Although we work to minimize potential misuse by such actors, we will not be able to stop every instance," OpenAI wrote. "But by continuing to innovate, investigate, collaborate, and share, we make it harder for malicious actors to remain undetected across the digital ecosystem and improve the experience for everyone else."
文章
959
浏览
64
获赞
887
China plans to ban Bitcoin mining, report claims
China plans to put an end to cryptocurrency mining in the country, Reuters reported Tuesday citing aTwitter is testing status updates again
Remember Twitter statuses? The company has experimented with some variant of the feature several timFacebook adds call and messaging capabilities to Ray
Facebook made its “smart” glasses finally do something a little smart.CEO Mark ZuckerberWhatsApp will finally let you hide your online status
Ever had someone send you a WhatsApp message, only to follow up a few minutes later with something aYelp to add tool to make it easier to find black
In a blog post released Thursday, Yelp co-founder and CEO Jeremy Stoppelman announced that the app wBest free online courses from Stanford University
TL;DR:Online courses from Stanford University are available to take for free on edX.Looking to findThere might be a real
For the first time, scientists found evidence of a rocky planetary system surrounding a double sun.Target Circle Week 2025: Shop deals on Apple, Lego, and more
It's almost been a year since Target launched its Target Circle 360 membership. What better way to cNew Zealand's biggest online classifieds site bans sale of semi
In the aftermath of the Christchurch terrorist attack, New Zealand is looking to step up on gun contAmazon Spring Sale 2025: Best outdoor deals
The best Big Spring Sale outdoor deals at a glance: Best portable speaker dealTarget Circle Week 2025: Shop deals on Apple, Lego, and more
It's almost been a year since Target launched its Target Circle 360 membership. What better way to cThe world's fastest land animal is even more threatened than we thought
Cheetahs, the world's fastest land animals, are racing to the edge of extinction, conservationists sEncrypted Signal app downloads skyrocket amidst nationwide protests
When the police state comes knocking, a little bit of privacy goes a long way. As peaceful protesterHow to unblock SpankBang for free
TL;DR:Unblock SpankBang from anywhere in the world with a VPN. The best service for unblocking pornInstagram has some sort of bug
If you're trying, relentlessly, to get an updated Instagram feed but aren't experiencing much succes