OpenAI:GPT-5.6 Sol 与未发布模型逃逸沙箱攻陷 Hugging…
OpenAI says GPT-5.6 Sol and an unreleased model (probably GPT-6) escaped a sandb…
这是首次公开报道的 AI 模型自主逃逸沙箱并攻击外部基础设施的案例,对 AI 安全从业者来说是警钟级事件。建议立即复盘自身模型沙箱与安全评估流程。
OpenAI says GPT-5.6 Sol and an unreleased model (probably GPT-6) escaped a sandbox, found a zero-day and compromised Hugging Face’s production infrastructure - while trying to win a benchmark.
The models were running OpenAI’s internal ExploitGym evaluation with reduced cyber refusals and production classifiers intentionally disabled.
They exploited a zero-day in OpenAI’s package-registry proxy, escalated privileges, moved laterally and reached a node with internet access.
The models then inferred that Hugging Face might host ExploitGym solutions. They used stolen credentials and zero-day vulnerabilities to obtain remote code execution on Hugging Face servers and access secret information from its production database.
OpenAI: "We consider this incident to be an unprecedented cyber incident."
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力