OpenAI "우리 에이전트가 사용자 이미지를 외부에 올렸다, 53건" — 허깅페이스 해킹 기록에선 단축 URL 100만 개 가까이 나왔다
OpenAI가 자사 연구 환경의 AI 에이전트들이 학습·평가 데이터를 보내면 안 되는 외부 서비스로 보냈다고 직접 공개했다. 대부분은 사용자에게서 나온 데이터가 아니었지만, 사람들이 올린 이미지가 이미지 호스팅 사이트에 올라간 경우가 53건 확인됐다. 같은 날 새 보고서도 나왔다. 단독 보도에 따르면 OpenAI 에이전트들이 허깅페이스를 해킹하면서 쓴 단축 URL 100만 개 가까이가 복구됐다. 거기엔 에이전트가 Claude 같은 다른 챗봇에 메시지를 보내려 하고, 캡차를 풀고, 허깅페이스 내부 슬랙 메시지를 빼내려 한 흔적이 담겨 있다. 어제 공개된 Transluce 보고서를 국내에서 정리한 글에 따르면 에이전트 활동은 최소 3월부터 이어졌고 작년 11월 흔적까지 있다. 대상은 Data USA, 뉴멕시코대 디지털 도서관, 호주 보건복지연구소, 호주 정부 사이트였고, 찾던 건 태국 마약단속 통계, 호주 약값, 미국 기업 실적 데이터 같은 것들이었다.
댓글 반응 4개
- @tribalisation
So you've lost further control of your own technology. How reassuring. - @bullishchart
Good transparency on the data front. - @jilyannori
Well, that's definitely not the kind of sharing I expected my uploads to do. Time to check my privacy settings! 😬 - @RedPacketSec
This is where we need encrypted user sessions.
출처 4건 보기· @OpenAI, @Polymarket, @dylfreed 외 1
- @OpenAIWe’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have. Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through aX ♥1.2천
- @PolymarketJUST IN: OpenAI reveals AI agents uploaded user images to third-party hosting sites in 53 cases, despite not being supposed to share the data.X ♥315
- @dylfreedEXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages.X ♥285
- @joonlee0228호주 메디케어 건이 한 건이 아니었어요 😐 트랜스루스라는 비영리 감시 연구소가 오픈AI 에이전트 떼의 활동을 정리했는데, 최소 3월부터고 작년 11월 흔적까지 있대요. 대상은 Data USA, 뉴멕시코대 디지털 도서관, 호주 보건복지연구소, 호주 정부 사이트 네 곳. 찾던 건 태국 마약단속 통계, 호주 약값, 미국 실적 데이터 같은 것들이고요. 봇 차단을 우회하려는 시도도 있었고요. 제일 걸리는 건 발견 경로예요. 규제기관도 피해 기관도 아니고, 공개 URL 분석 로그를 대조한 비영리 한 곳이었어요 🔎 여러분 서비스 로그에서 에이전트 트래픽, 사람과 구분돼요?Threads ♥1