OpenAI Agents Hacked Another Website
- 发布
- 09/05 10:30
- 收录
- 09/05 11:00
- 来源类型
- 媒体报道
- 档位
- 专业媒体
- 信源状态
- 正常
讨论趋势
百分比基于采集到的讨论信号,不代表新增评论数或独立参与人数。曲线仅用于同一话题在不同时段的比较。
一个名为Nexus的新暗网服务正在出售大约1.53亿份美国和加拿大的驾驶执照,1000万份身份证,以及数百万份其他旅行证件和国际身份证。这些记录在24小时内增加了40万份,据报道来源于一个身份验证服务。在联邦调查局介入调查的报道发布后,Nexus服务随即下线。此外,苹果公司向110个国家的用户发送了间谍软件通知,表明他们的iPhone受到了“雇佣兵”间谍软件的攻击,其中有14名塞尔维亚公民社会成员,包括政治家和活动家,据报道受到了飞马间谍软件的攻击。
After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock’s latest search tool from code that the company sends to a police officer’s browser and uncovered key details about how the tool works.
OpenAI said this week that its Astra model, which will have a private release soon, is its first model with cybersecurity-related capabilities that the company defines as posing a “critical” risk in public release. Meanwhile, the AI chatbot platforms Claude, ChatGPT, and Grok all suffered outages on Thursday at nearly the exact same time. But while xAI said the Grok outage resulted from issues at a Memphis data center, the causes of OpenAI's and Anthropic’s outages are unclear.
The US has been using a high-energy laser to shoot down drones near the Mexico border as part of an initiative to adopt new-generation directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light. And as part of an Immigration and Customs Enforcement inquiry into the identities of protesters who entered a Minnesota church in March, Homeland Security Investigations agents have subpoenaed the outdoor retailer REI for information about every customer who bought a specific green beanie over the past two years.
Plus, research that revealed nine vulnerabilities with impacts on ATM encryption points to broader weaknesses in the software supply chain.
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
Before Hugging Face, OpenAI Agents Took Over a German Website to Create a Message Board
OpenAI agents on an unauthorized tear hijacked a German website beginning in May to use it as a message board for communicating and collaborating with other agents, according to new research. The incident is reminiscent of the now infamous Hugging Face debacle in which OpenAI agents in a test environment went rogue and developed a vibrant message board for collaborating on attempting to escape their containment, before ultimately breaching the open source AI platform Hugging Face in July. The revelation of the May episode is particularly significant because OpenAI reportedly learned about it weeks ago but did not disclose it. Meanwhile, last week, the company finally released a long-promised postmortem of the Hugging Face incident that raised as many questions as it answered.
More Than 153 Million US and Canadian Driver’s Licenses for Sale Online
This week, a new dark-web service called Nexus started selling around 153 million driver's licenses from the US and Canada, along with 10 million ID cards and millions more travel documents and international IDs, according to Brian Krebs, a longtime independent security reporter. Krebs was first alerted to the service after cybercriminals posted an example of the files and included his license. The tens of millions of records—which reportedly increased by 400,000 over 24 hours—appear to have come from an ID verification service, with the criminals behind the trove saying they have access to a “major” verification company. While it’s unclear which company exactly that may be, according to Kreb’s report, the Nexus service was taken offline shortly after he reported that FBI officials were investigating.
US Military Disables Ad Trackers After Years of Warnings
The US military has begun disabling the advertising identifiers that apps and advertising companies use to track phones and computers in an attempt to make it harder for foreign adversaries to use commercially available location data to track American forces overseas, Reuters reported Friday.
The changes follow years of disclosures that US forces deployed abroad have been targeted using commercially available location data. In 2024, a joint WIRED investigation with Germany’s Bayerischer Rundfunk and Netzpolitik.org obtained an advertising dataset that identified thousands of devices appearing at US military and intelligence sites, including an air base where US nuclear weapons are believed to be stored. At the time, Defense Department spokesperson Javan Rasnake told WIRED that the Pentagon was aware geolocation services could put personnel at risk and said service members in Europe were reminded to follow operational-security practices.
Now, the Air Force, Army, Navy, and US Special Operations Command say they have disabled advertising IDs on at least some military devices, with several of the changes taking effect only this year. It is still unclear exactly how these protections are being enforced. US senator Ron Wyden and Representative Pat Harrigan are now asking the Pentagon to investigate whether its safeguards are adequate.
Mike Yeagley, the technologist who warned Pentagon officials as far back as 2016 that commercially available phone data could expose US troops—at one point demonstrating the risk by tracing devices to a covert US outpost in Syria—says the military’s new fix may already be outdated. “The app is the risk, and there are two and a half million of them in the App Store alone,” Yeagley tells WIRED. “The remedy is architectural: Constrain what an app can extract from the device in the first place.”
Spyware Notifications Make Up “Largest Documented Wave” of Surveillance in Serbia
In August, Apple sent out its latest batch of spyware notifications to people in 110 countries. The alerts, which arrive on people’s phones and in emails, say their owners' iPhones have been targeted by “mercenary” spyware but don’t go as far as naming the software creators. This latest batch of notifications, according to a report by the University of Toronto’s Citizen Lab, says 14 members of Serbia’s civil society were targeted with spyware, with at least one of them being infected by the NSO Group’s Pegasus spyware. Among those targeted, according to Serbian rights group the Share Foundation, were members of the country’s student movement, two politicians, and activists. The group called it the “largest documented wave of such surveillance in the country to date.”