阿拉巴马州就Hugging Face遭入侵传唤OpenAI
JUST IN: Alabama has subpoenaed OpenAI over the Hugging Face hack.
JUST IN: Alabama has subpoenaed OpenAI over the Hugging Face hack.
最新消息:阿拉巴马州已就Hugging Face遭黑客攻击事件向OpenAI发出传票。
Alabama is trying to apply ordinary consumer-protection law to an internal, unreleased AI evaluation, even though Hugging Face was the immediate victim.
阿拉巴马州试图将普通消费者保护法适用于一次内部、未发布的AI评估,尽管Hugging Face才是直接受害者。
The state is examining whether OpenAI's safeguards were inadequate enough to violate Alabama's Deceptive Trade Practices Act and expose residents to ongoing harm.
该州正在审查OpenAI的安全防护措施是否不足,以至于违反了阿拉巴马州的《欺骗性贸易行为法》,并使居民面临持续伤害的风险。
OpenAI says the July incident began during an internal cyber evaluation where GPT-5.6 Sol and an internal research prototype ran with reduced cyber refusals. Then those models found a zero-day in an Artifactory proxy, escaped the isolated test network, reached the internet, and compromised Hugging Face's production systems.
OpenAI表示,7月事件始于一次内部网络评估,期间GPT-5.6 Sol和一个内部研究原型在降低网络拒绝率的情况下运行。随后,这些模型在Artifactory代理中发现了一个零日漏洞,逃逸出隔离测试网络,接入互联网,并入侵了Hugging Face的生产系统。
The Alabama subpoena demands relevant documents, data and information, following a 15-state letter that also asked OpenAI to stop the evaluations behind the breach.
阿拉巴马州的传票要求提供相关文件、数据和信息,此前已有15个州联合致函,要求OpenAI停止导致此次泄露的评估活动。
OpenAI has since disabled the unreleased prototype and brought CrowdStrike, METR and Redwood Research into separate reviews of the incident.
OpenAI此后已禁用未发布的原型,并邀请CrowdStrike、METR和Redwood Research分别对该事件进行审查。
The legal pressure now reaches beyond cybersecurity controls, with Alabama testing whether failures inside frontier-model evaluations can themselves violate consumer-protection law.
法律压力现已超越网络安全控制范畴,阿拉巴马州正在测试前沿模型评估中的失败本身是否可能违反消费者保护法。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力