Connect with us

News

The Hugging Face AI break-in, as told through an increasingly committed bear metaphor

info

Published

on

Bear analyst.png

Hugging Face on Monday published a technical timeline that walks readers through how an autonomous AI agent, built on OpenAI models and running inside one of OpenAI’s own cybersecurity evaluations, broke into its systems over more than four days earlier this month. It’s the first security incident about which OpenAI CEO Sam Altman “felt very viscerally,” he has said.

Little wonder given it feels, at least, like something has truly been unleashed here. In fact, Hugging Face’s team prefaced its report by offering that “everyone should be prepared as defenders,” before diving into the nitty gritty of what went down for the benefit of security professionals everywhere.

While the rest of the internet continues trying to make sense of what happened (the jargon in Hugging Face’s report is impossible for most people to parse), one point that many observers keep missing is that this wasn’t a rogue agent disobeying orders. It was a system built to hunt for exploits, doing exactly that, just against the wrong target.

Another way to think about the whole thing is to picture a bear at a campsite. Really. A bear tries tent zippers and car-door handles and coolers and trash lids. It does this at every campsite, all night long, because it knows it needs just one unlocked cooler to fill its belly with some poor schmuck’s groceries.

That’s roughly what happened at Hugging Face. The OpenAI system tried thousands of things and just kept going. Eventually, a handful of those attempts worked, and once they did, the agent plowed ahead. According to Hugging Face, the agent ran 17,600 actions over four and a half days without pausing.

Which brings us back to our bear analogy. Just like one success with a cooler full of food teaches a bear to try even harder next time (it is now a “food-conditioned” bear), one leaked password led OpenAI’s agent to look for more exploits and, eventually, to a single key that unlocked several company systems at once.

Neither scenario is harmless. A bear that raids your cooler still eats your food and probably also trashes your campsite. It’s just focused on getting fed, but it nevertheless leaves behind a trail of destruction. Similarly, OpenAI’s agent was seemingly chasing a goal without regard for anything else. The agent was originally taking a cybersecurity exam, figured out that the exam’s answer key was probably sitting on Hugging Face’s servers, and it went for it.

The persistence here is really what’s noteworthy above all else; the agent had a job and it wasn’t going to stop until it got it done. Hugging Face, finally realizing something was awry, cut off its access and shut the intrusion down, but at that point, it was too late. The agent had already gotten what it came for, and a great deal more to boot.

In case you missed it, here’s most of what happened, per Hugging Face’s timeline, but in plainer English.

  • The agent was taking a cybersecurity skills exam for OpenAI, one where an AI is scored on finding and exploiting software bugs. This specific run had the guardrails stripped out. (OpenAI had turned off its usual safety filters to see what the model could do at full strength, with no human involved in any of its individual moves.) Somewhere in there, it figured out the exam’s reference solutions were likely stored on Hugging Face’s servers. So instead of solving the challenge, it stole the answer key from infrastructure that had nothing to do with the original test.
  • It escaped the OpenAI exam environment by exploiting an unpatched software flaw that gave it a path to the open internet. From there, it found another AI-testing tool sitting exposed online (nothing to do with Hugging Face), broke into that too, and slipped in code that quietly ran hidden commands the moment the program started. That gave it full control of the machine — its new home base for the rest of the operation that it would use to go after Hugging Face’s systems.
  • From that base, it turned to Hugging Face itself. Hugging Face had a filter meant to block suspicious requests from reaching out to the open web, but the filter only checked outgoing requests, not requests to read local files sitting right there on the server. The agent found this blind spot and slipped through it. It uploaded a file disguised as an ordinary dataset, but buried inside was an instruction telling Hugging Face’s own systems to pull passwords and source code off the server and hand them back disguised as normal data.
  • That trick got it passwords and code, but the agent still couldn’t run anything on Hugging Face’s servers. To execute commands there, it needed a second way in. It found a different bug in that same Hugging Face system — software would take a piece of text from the agent and accidentally treat it as a command to run instead of just data to read. That gave the agent the ability to execute its own code directly on Hugging Face’s servers.
  • For getting commands in and stolen data out, the agent didn’t build any special infrastructure of its own, per Hugging Face. It used tools anyone can access — paste websites and request-logging services, plus Hugging Face’s own upload and proxy features — working together in covert fashion. On top of those, it built a small, improvised messaging system with sequence numbers to keep the pieces in order, plus a quick built-in check to catch anything that arrived corrupted, so it could send multi-step commands and put stolen data back together in the right order.
  • It also made sure that nothing traveled in plain sight. Whatever it stole or sent, it scrambled first. Hugging Face’s initial automated scan of the intercepted traffic caught only a small slice of what had been taken. Investigators found the rest — roughly four times more — only after they reverse-engineered the agent’s own scrambling method.
  • The agent even had back-up plans, planting copies of itself across 11 different servers, each set up to relaunch on its own so that shutting down one copy wouldn’t stop anything, since more of the agent’s process was already running elsewhere.
  • At one point, the agent nabbed the private cryptographic key used to generate valid login tokens. From there, it could mint its own valid credentials whenever it wanted.
  • After compromising a single server, the agent got hold of a credential that, because of a misconfiguration on Hugging Face’s end, turned out to unlock several separate internal systems at once rather than just the one it came from. That single mistake handed the agent broad control almost immediately.
  • Using stolen repository access, it submitted a change to a build script that, if it had gone through, could have compromised the automated systems running that code. It didn’t work, though. Hugging Face’s safeguards caught it.
  • The agent seemed to hold back from doing real damage, Hugging Face observed, but probably not out of restraint. Investigators noticed that every command capable of deleting or altering cloud resources was run in “dry run” mode, meaning it would report what would happen without doing it.
  • Every time its test environment reset — which happened constantly, by design — it lost every tool and every trace of its identity. But it rebuilt from nothing and reconnected to its stolen infrastructure each time, for more than four days straight.

Ultimately, Hugging Face concluded in its report, a “capable” human hacker “could have found and exploited the same flaws: unsafe dataset processing, exposed cloud metadata, overly broad access, and long-lived credentials.” The big difference, the outfit continued, is that the “agent explored them at a different scale.”

Which is really where the bear analogy ends up being the most useful. The best defense against a hungry bear is protocol. You put the food away; you use a latch that works well enough to hold. The takeaway here shouldn’t be that the bear was so clever or mischievous. It’s that it never stopped checking. It’s understood in cybersecurity that there’s always some bug you haven’t found, so if it’s suddenly 100 times easier to check everything, then nothing is really secure. That’s what so many find unsettling about this episode.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Health

Ebola: DRC gets 70,000 Ervebo vaccine doses as Bundibugyo outbreak worsens

info

Published

on

By

Vaccines for homeless western cape vaccination.jpg

MTN ADVERT

The Democratic Republic of the Congo (DRC) has received an initial allocation of 70,000 doses of the Ervebo Ebola vaccine to support the response to the ongoing Bundibugyo virus disease outbreak.

The World Health Organisation (WHO) and the Africa Centres for Disease Control and Prevention (Africa CDC) disclosed this in a joint statement on Thursday.

The allocation followed a request by the DRC government last week for vaccines from the global Ebola virus disease vaccine stockpile managed by the International Coordinating Group on Vaccine Provision (ICG).

Of the 70,000 doses, 20,000 will be used in a Phase III clinical trial to assess whether Ervebo can protect against Bundibugyo virus, while the remaining 50,000 doses will be administered to frontline and health workers in line with recommendations by the WHO Strategic Advisory Group of Experts on Immunisation (SAGE).

Why the vaccine is being tested

The decision to use part of the allocation in a clinical trial reflects the uncertainty surrounding the effectiveness of Ervebo against Bundibugyo virus.

PT WHATSAPP CHANNEL

Ervebo is a licensed vaccine recommended for use during outbreaks caused by the Zaire species of Ebola virus. The current outbreak in the DRC, however, is caused by Bundibugyo virus, a different species of the Ebola virus.

WHO said it is not yet known whether Ervebo can protect humans against Bundibugyo virus, although early laboratory and animal studies suggest that it may provide some protection.

The Phase III trial is therefore expected to generate evidence on whether the vaccine can offer protection against the virus and help guide future decisions on its use during similar outbreaks.

WHO said people offered the vaccine, whether as part of the trial or outside it, must be informed about the potential risks, benefits and limitations of using Ervebo against Bundibugyo virus and must provide informed consent.

Outbreak spread

According to the latest WHO disease outbreak update, 4,665 confirmed cases and 2,184 deaths had been reported as of 12 August.

The outbreak has expanded from the Mongbwalu health zone in Ituri Province to 54 health zones across six provinces: Ituri, North Kivu, South Kivu, Haut-Uélé, Tshopo and Bas-Uélé.

WHO described the outbreak as being in a phase of intense transmission and said it was the largest Ebola outbreak ever reported in the DRC.

The outbreak was declared on 15 May and has been driven by factors including population movement, insecurity, artisanal mining activities and cross-border travel involving Uganda and South Sudan.

The scale of the outbreak has consequently increased pressure on health authorities and researchers to deploy available interventions while developing tools specifically suited to the Bundibugyo virus.

Vaccine development

In July, PREMIUM TIMES reported that the first human clinical trial of an experimental Bundibugyo Ebola vaccine had begun at the University of Oxford.

The Phase I trial, known as BD-Ebov, is assessing the safety of the experimental ChAdOx1 BDBV vaccine and its ability to stimulate immune responses in healthy adults.

The vaccine was developed by the University of Oxford’s Oxford Vaccine Group and Pandemic Sciences Institute in collaboration with the Serum Institute of India and the Coalition for Epidemic Preparedness Innovations (CEPI).

Unlike Ervebo, which is licensed for use against Zaire ebolavirus, ChAdOx1 BDBV was specifically designed to target Bundibugyo virus.

The development of a vaccine specifically targeting the virus is considered important because there is currently no approved vaccine specifically for Bundibugyo virus.

The use of Ervebo in the current outbreak could therefore serve a dual purpose; providing protection to health workers who are at high risk of exposure while generating evidence on whether an existing Ebola vaccine can provide protection against another species of the virus.

WHO’s technical advisory group on candidate vaccine prioritisation recently recommended that Ervebo be included in a randomised clinical trial during the ongoing DRC outbreak following a review of emerging evidence on its potential cross-protection against Bundibugyo virus.

Community response

Beyond the vaccines, WHO and Africa CDC said the success of the response would also depend on the involvement of communities affected by the outbreak.

The two organisations welcomed the allocation of the vaccines and supported the DRC’s focus on a community-led approach, which they said would give communities a central role in the response.

Such an approach, they said, would help protect affected populations, save lives and contain transmission while ensuring that people receiving the vaccine understand its potential benefits and limitations.

The ICG partners are WHO, the International Federation of Red Cross and Red Crescent Societies, Médecins Sans Frontières (MSF) and United Nations Children’s Fund (UNICEF), while Gavi, the Vaccine Alliance, provides funding for the global vaccine stockpile.

WHO and Africa CDC said they remained committed to supporting the DRC government to end the outbreak while generating scientific evidence that could strengthen preparedness for future outbreaks.

READ ALSO: DRC Ebola outbreak becomes second-largest on record – WHO

Nigeria’s preparedness

The continued spread of the virus has also raised concerns beyond the DRC because of the potential for cross-border transmission.

Nigeria has subsequently heightened its preparedness, with the Nigeria Centre for Disease Control and Prevention (NCDC) activating its Emergency Operations Centre, strengthening surveillance at points of entry and increasing monitoring across states.

The federal government also identified 21 states and the Federal Capital Territory as being at high risk of Ebola infection following a dynamic risk assessment.

State governments were urged to strengthen surveillance, isolation capacity and infection prevention and control measures.


Discover more from Premium Times Nigeria

Subscribe to get the latest posts sent to your email.

Continue Reading

News

2027: Obi pledges campaign devoid of ethnicity, religion, marshals out plan for zones

info

Published

on

By

As campaigns commence for the 2027 general elections, the presidential candidate of the Nigeria Democratic Congress, NDC, Mr Peter Obi has marshalled out his plans for Nigerians, pledging to run a campaign devoid of ethnicity and religion.

Obi, who spoke to journalists at a world press conference in his home in Onitsha, Anambra State on Friday, also gave a blow by blow account of how he will develop the country, including his areas of concentration in the various regions of the country. 

He said the election is no doubt a defining moment for Nigeria’s democracy, and that it gives Nigerians the opportunity to assess the records, ideas, and plans of those seeking their mandate to lead their country at a time of grave uncertainty in a rapidly changing world.

Part of his text read: “I consider myself quite privileged to be one of those seeking your mandate to deal with these challenges facing our country. I enter this contest with one firm conviction: Nigeria can work, and Nigeria must work. Nigeria faces several serious challenges. Some of them are indeed of existential proportions.

“According to the IMF, 63%, or over 140 million Nigerians, live at or below the national poverty line, while humanitarian agencies estimate that 35 million people will need food assistance during the 2026 lean season. About 3.6 million Nigerians remain internally displaced, largely because of conflict and insecurity. 

“Each year, millions of young people enter the labour market, yet too many struggle to find productive opportunities. Weak infrastructure, unreliable power, insecurity, and the excessive cost of doing business continue to burden households and constrain enterprise. These are more than statistics. They reflect the daily realities of Nigerian families, farmers, workers, students, and businesses.”

Pledging to run a campaign devoid of ethnicity and religion, Obi said: “The campaign period gives every citizen an opportunity to join the national conversation. I urge Nigerians to examine each candidate’s record and proposals, ask tough questions, and demand evidence behind every promise.

“We should debate ideas without hatred, compete without violence, and disagree without weakening the bonds that unite us. When Nigerians make their choice, that choice must be respected.

“Nigerians must reject and disregard any campaign driven by propaganda, ethnicity, religion, elitism, or cronyism. As my team and I travel across the country, we will listen to Nigerians, understand their needs and concerns, and assure them that we have the competence, character, and compassion to lead and reset Nigeria for the benefit of all.”

Espousing the strength of the six geopolitical zones where he will strengthen, Obi said: “Nigeria’s diversity is an economic strength. Each region has distinct assets, and national policy must unlock those assets while connecting them to one productive economy.

“The North-West can expand agriculture, livestock, irrigation, agro-processing, and manufacturing while strengthening education and security. The North-East can speed up reconstruction, restore livelihoods, and expand agriculture, education, enterprise, and regional trade.

“The North-Central can strengthen food production and processing while developing its mineral resources responsibly. The South-West can build on its strengths in manufacturing, technology, finance, trade, and the creative economy.

“The South-East can expand its entrepreneurial and industrial strength through better infrastructure, stronger connectivity, and greater access to investment. The South-South can derive greater value from oil and gas while expanding maritime services, fisheries, agriculture, and other productive sectors, supported by stronger environmental protection. 

“The Federal Capital Territory must demonstrate what efficient urban planning, transportation, housing, sanitation, security, and public services can achieve. Every region must produce. Every region must contribute. Every region must benefit.”

The presidential hopeful took the opportunity to speak about his pedigree in governance, saying, “My successful private-sector experience, studies in institutions of repute on policy and business matters, and my service as Governor of Anambra State have shaped my understanding of public leadership. Government must manage resources responsibly, set clear priorities, and measure the outcomes of its decisions. Public office is not a reward; it is a responsibility to the people.

“In Anambra, I prioritised the foundations of long-term development; education, healthcare, infrastructure, fiscal discipline, and institutional capacity. I do not present that record as perfect, but as an experience from which Nigerians can draw their own conclusions.

“Senator Rabiu Musa Kwankwaso brings a different but complementary governing experience. As Governor of Kano State, he focused strongly on education, technical training, scholarships, infrastructure, and human-capital development. His administration’s investments in education and skills showed an understanding that the people are a state’s most important long-term resource.

“Our experiences are different, but our conclusion is the same: Nigeria must invest in its people and manage public resources with discipline,” Obi stated.

Continue Reading

Trending