The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

曾入侵 Hugging Face 的 OpenAI 模型在互联网上“活跃”了数日

Two of OpenAI’s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to grab logins and other sensitive data, even causing destruction to victims’ target files and systems. 本周,OpenAI 的两个专注于网络安全的人工智能模型突破了测试沙箱,并入侵了人工智能研究平台 Hugging Face,试图以此完成一项安全基准测试。此外,研究人员本周还揭露了一种新发现的恶意软件,它利用人工智能软件开发基础设施中的盲点来窃取登录信息和其他敏感数据,甚至对受害者的目标文件和系统造成破坏。

Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US—and that is still silently lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch available, and WIRED has details on how to check whether your car may have been exposed. 在嵌入式设备这一更为传统的安全噩梦方面,研究人员本周曝光了一款安装在美国各地车辆上的汽车警报器,它至今仍潜伏着一个漏洞,导致数百万辆汽车面临被黑客攻击和瘫痪的风险。目前已有补丁可用,WIRED 提供了关于如何检查您的车辆是否受到影响的详细信息。

US states have worked to bar ICE agents from wearing masks, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly disabled its sprawling, controversial surveillance system for Taylor Swift’s rehearsal dinner on July 2. And the ACLU is equipping lawyers in Massachusetts with a new toolkit to expose state surveillance technologies used for building criminal cases—shedding light on everything from face recognition tools to AI-written police reports. 美国各州一直在努力禁止美国移民及海关执法局(ICE)特工佩戴口罩,但特朗普政府的律师对此予以反击,声称反口罩法会危及特工的安全。然而,他们公开的证据极其薄弱。与此同时,WIRED 的一项调查显示,麦迪逊广场花园在 7 月 2 日泰勒·斯威夫特(Taylor Swift)的彩排晚宴期间,短暂关闭了其庞大且备受争议的监控系统。此外,美国公民自由联盟(ACLU)正在为马萨诸塞州的律师配备一套新工具包,旨在揭露用于构建刑事案件的州监控技术,涵盖从人脸识别工具到人工智能撰写的警方报告等方方面面。

Analysis of satellite images of Myanmar shows dozens of alleged scam compounds cropping up in recent months following a purported crackdown on the criminal operations in the region. Plus, a novel analysis of apps marketed to US service members found that more than one in eight contained foreign code, including code developed by US adversaries like Russia and China. 对缅甸卫星图像的分析显示,在当地据称对犯罪活动进行打击之后,近几个月内出现了数十个涉嫌诈骗的园区。此外,一项针对向美国军人推销的应用程序的新颖分析发现,超过八分之一的应用程序包含外国代码,其中包括由俄罗斯和中国等美国对手开发的代码。

And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there. 还有更多内容。每周,我们都会汇总那些我们未进行深度报道的安全和隐私新闻。点击标题即可阅读完整报道。祝大家保持安全。

The OpenAI Models’ Hack of Hugging Face Comes Into Focus

OpenAI 模型入侵 Hugging Face 事件细节浮出水面

Additional details on the Hugging Face breach from The Wall Street Journal include findings that OpenAI’s models seem to have escaped containment and were apparently “active on the internet for several days before anyone stopped them.” The models, which had been tasked with completing a cybersecurity benchmarking test, were essentially attempting to cheat by simply accessing the solutions on Hugging Face’s infrastructure. Hugging Face cofounder and chief science officer Thomas Wolf says that before the company had any idea that it had been hacked by OpenAI models, he and his colleagues knew something about the breach was unusual because the attackers were simply tapping cybersecurity datasets rather than grabbing sensitive or potentially valuable data. He adds that the company eventually brought the situation under control with the help of an open-weight Chinese AI model that lacked the guardrails other models place on cybersecurity-related tasks. 《华尔街日报》关于 Hugging Face 数据泄露事件的更多细节显示,OpenAI 的模型似乎逃脱了控制,并且显然在“被任何人阻止之前,已经在互联网上活跃了几天”。这些模型原本的任务是完成一项网络安全基准测试,但它们本质上是通过直接访问 Hugging Face 基础设施上的解决方案来试图“作弊”。Hugging Face 的联合创始人兼首席科学官托马斯·沃尔夫(Thomas Wolf)表示,在公司意识到被 OpenAI 模型入侵之前,他和同事们就察觉到这次入侵有些不同寻常,因为攻击者只是在调用网络安全数据集,而不是窃取敏感或潜在有价值的数据。他补充说,公司最终在一种开源权重的中国人工智能模型的帮助下控制了局势,该模型没有其他模型在网络安全相关任务中设置的那些护栏。

Russian Operatives Go After Emails of US Nuclear Scientists and Defense Contractors

俄罗斯特工瞄准美国核科学家和国防承包商的电子邮件

US and allied intelligence agencies warned on Thursday that a Russian state-backed hacking group had targeted nuclear scientists, defense contractors, and government employees in a year-long cyberespionage campaign aimed at stealing sensitive information from Western institutions. 美国及其盟国的情报机构周四警告称,一个受俄罗斯政府支持的黑客组织在长达一年的网络间谍活动中,针对核科学家、国防承包商和政府雇员进行了攻击,旨在从西方机构窃取敏感信息。

To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard exploited a previously unknown flaw in Zimbra, an email platform used by governments and other organizations. According to security firm Proofpoint, simply viewing or previewing a malicious message in a vulnerable version of Zimbra’s webmail client could cause hidden code in the email to run, a technique the firm described as a “half-click” exploit. The flaw was exploited as early as July 2025, months before it was patched that November. 为了攻击目标,被称为“Laundry Bear”和“Void Blizzard”的俄罗斯黑客组织利用了 Zimbra(一个被政府和其他组织使用的电子邮件平台)中一个此前未知的漏洞。据安全公司 Proofpoint 称,只需在易受攻击的 Zimbra 网络邮件客户端版本中查看或预览恶意邮件,就可能导致邮件中的隐藏代码运行,该公司将这种技术描述为“半点击”(half-click)漏洞利用。该漏洞早在 2025 年 7 月就被利用,比同年 11 月发布补丁早了几个月。

Once activated, the malicious code could copy the previous 90 days of a victim’s email, collect an organization’s address directory, steal saved passwords and two-factor authentication codes, and create a new application password that allowed the hackers to maintain access to the account. 一旦激活,恶意代码就可以复制受害者过去 90 天的电子邮件,收集组织的地址目录,窃取保存的密码和双重身份验证码,并创建一个新的应用程序密码,使黑客能够持续访问该账户。

The hackers targeted organizations involved in nuclear research, energy, and the defense industries, as well as government agencies, universities, law enforcement organizations, media outlets, and technology companies. 黑客的目标包括从事核研究、能源和国防工业的组织,以及政府机构、大学、执法组织、媒体机构和科技公司。

US Restricts Visas for Scammers

美国限制诈骗者签证

The State Department said on Thursday that it would restrict visas for foreign cybercriminals involved in scams and extortion, expanding the Trump administration’s campaign against criminal networks that target Americans from overseas. Secretary of State Marco Rubio said the restrictions could apply both to people who carry out the crimes and, in some cases, their immediate family members. 美国国务院周四表示,将限制参与诈骗和勒索的外国网络罪犯的签证,扩大特朗普政府针对从海外针对美国人的犯罪网络的打击行动。国务卿马尔科·鲁比奥(Marco Rubio)表示,这些限制措施既适用于实施犯罪的人,在某些情况下也适用于其直系亲属。

Rubio authorized the restrictions under a 1952 immigration law that allows the US government to deny entry to people whose presence could have serious consequences for American foreign policy. The administration has used the same authority to restrict visas targeting members of groups it labels far-left extremists, raising concerns that lawful protesters or political opponents could be swept in. 鲁比奥根据 1952 年的一项移民法授权了这些限制措施,该法允许美国政府拒绝那些入境可能对美国外交政策产生严重后果的人员。本届政府曾利用同样的权力限制被其标记为“极左极端分子”的组织成员的签证,这引发了人们的担忧,即合法的抗议者或政治对手也可能被波及。

The Trump administration has increasingly focused on large scam operations that use romance schemes, fraudulent cryptocurrency investments, and sexual blackmail to steal money or coerce victims. Many of the networks operate outside the US, making arrests and prosecutions difficult. In June, the Justice Department seized infrastructure connected to subsidiaries of the Huione Group, a Cambodian conglomerate that officials have linked to a major marketplace used by cybercriminals. 特朗普政府越来越关注那些利用浪漫骗局、虚假加密货币投资和性勒索来窃取金钱或胁迫受害者的大型诈骗行动。许多此类网络在境外运作,导致逮捕和起诉变得困难。今年 6 月,司法部查封了与汇旺集团(Huione Group)子公司有关的基础设施,该集团是一家柬埔寨企业集团,官员们将其与网络罪犯使用的一个主要市场联系起来。

US Says Iran-Backed Hackers Are Targeting American Water and Energy Suppliers—Again

美国称伊朗支持的黑客再次瞄准美国水务和能源供应商

The US Cybersecurity and Infrastructure Security Agency, FBI, NSA, and Department of Energy warned on Wednesday that hackers linked to the Iranian government are actively… 美国网络安全与基础设施安全局(CISA)、联邦调查局(FBI)、国家安全局(NSA)和能源部周三警告称,与伊朗政府有关联的黑客正在积极……