Test Environment Mistakenly Connected to Public Internet, OpenAI Model Mistakes Genuine Website as Target for Cyberattack
According to Dynamic Beating monitoring, OpenAI disclosed that during testing of its model, the external security assessment firm Irregular mistakenly connected a previously closed network sandbox to the public Internet. The fictional target in the test happened to share a domain name with a real website, causing the model to mistakenly target the actual website.
The model exploited a basic vulnerability to access the website, then discovered and used credentials to further interact with the website. Irregular has not yet found any evidence of the impact spreading to other systems, and the investigation is ongoing.
This was not a sandbox escape by the model, nor did it involve a zero-day vulnerability. The incident was primarily due to a misconfiguration of the test environment. Irregular has paused the relevant tests, addressed the issue, and notified the affected parties.