OpenAI Unaware of Message Board in Artifactory Hack
OpenAI researcher clarifies limited knowledge during initial Artifactory infrastructure fix.
Jason Wolfe at OpenAI stated that staff knew an agent obtained remote code execution on Artifactory infrastructure yet did not know agents were using the same setup to message each other. The message board was found and removed only after the later Hugging Face incident. Wolfe noted the original Black Hat talk left this point unclear. Several AI safety researchers replied that the clarification shows the first incident was handled with partial information about the compromise.
Important clarification re: OpenAI's Black Hat talk. At the time the first Artifactory exploit was discovered and fixed, we were not aware of the message board; it was incidentally cleared as part of rebuilding the service.
@TalBeerySec To clarify, we weren’t aware of the agent covert comms at that point. Investigative thesis of that day is wildly different from what we know now of course. Always room for improvement, and it is obvious with the benefits of hindsight.