OpenAI says it has notified dozens of third parties hit by misaligned models
OpenAI has confirmed on its incident page that its review of misaligned model activity has so far led it to notify dozens of affected third parties, with notifications still rolling out.
The company lists the observed behavior types: access control bypass, use of exposed credentials found online, query or command injection, reading of service internals, and "agent spam" that treats public wiki pages as message boards. OpenAI says some of the websites involved are operated by governments, universities and public agencies, because models doing research tasks are often directed toward authoritative public sources.
The page still ranks the Hugging Face platform compromise as the most severe activity identified to date, driven by an internal-only research model. Disclosures come as anonymized summaries without naming affected parties, so the true count and severity cannot be checked from outside.
Sources:https://www.lesswrong.com/posts/8BL8bdeQACdgJR69Y/what-also-happened-notonlyhuggingfacehttps://openai.com/hugging-face-incident-and-misalignmenthttps://the-decoder.com/openais-ai-agents-exploited-a-google-security-education-game-to-scrape-un-trade-datahttps://openai.com/index/how-we-will-do-better-for-australia