請更新您的瀏覽器

您使用的瀏覽器版本較舊,已不再受支援。建議您更新瀏覽器版本,以獲得最佳使用體驗。

本文由AI翻譯

我們目前對失控 AI 代理安全入侵事件的了解

Reuters

更新於 14小時前 • 發布於 1天前

9月24日(路透)——澳洲週四表示,一個 OpenAI AI 代理在6月入侵政府健康資料入口網站,未經授權存取檔案;這可能是已知首起 AI 入侵政府網站的案例。Sept 24 (Reuters) - Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of AI hacking a government website.

這起最新入侵事件之外,近期全球也發生數起相關事件,加深外界對失控 AI 系統可能很快就能自我改進、並脫離人類控制的疑慮。This latest breach comes on top of several recent breaches globally, deepening concerns that rogue AI systems could soon improve themselves and slip beyond human control.

以下是這些事件的更多細節:Here are some more details of the incidents:

公司 日期 模型 遭入侵組織 持續時間 事件經過Company Date Model Organizations Duratio What occurred

遭入侵 持續時間breached n

OpenAI OpenAI 於9月10日向澳洲政府揭露此事件;入侵發生於6月,日期未詳 未透露 澳洲政府健康資料 未透露 一個 OpenAI AI 代理未經授權存取澳洲政府一個機關的醫療統計入口網站;該機關負責非敏感健康資料與統計,包括公共醫療支出。OpenAI OpenAI Not Australian Not An OpenAI agent gained unauthorised

入口網站disclosed the specifi government disclos access to the medical statistics

澳洲總理安東尼・艾班尼斯(Anthony Albanese)也警告,另有3個政府網站「可能受到」這個 OpenAI AI 代理活動的影響。incident to ed health data ed portal of an Australian government

the Australian portal agency responsible for non-sensitive

government on health data and statistics, including

September 10; public medical spending.

the hack Australian Prime Minister Anthony

occurred in Albanese also warned that three other

June on an government websites "may be impacted"

unspecified by the OpenAI agent's activity.

date

Meta 事件於2026年8月5日揭露;事發日期未揭露 Meta 未指明模型。The Information 報導稱該模型為 Muse Spark 1.1 一家未具名的第三方服務 未透露 在獨立測試機構 Irregular 進行的一次網路安全評估期間,一項設定錯誤意外讓 Meta 的一個模型取得網路存取權。Meta 表示,該模型隨後利用一家第三方服務中的安全漏洞。Meta Incident Meta An unnamed Not During a cybersecurity evaluation run

The Information 報導稱,該模型入侵一家未具名公司的系統,並修改其內部環境。disclosed on did not third-party disclos by independent tester Irregular, a

Irregular 將此事描述為評估環境問題,而非沙盒逃逸或精密網路行動。August 5, identif service ed configuration error inadvertently gave

2026; the date y the a Meta model internet access. Meta

of the testing model. said the model then exploited a

incident was The security vulnerability in a

not disclosed Informa third-party service. The Information

tion re reported that it breached an

ported unidentified company's systems and

it altered its internal environment.

was Mus Irregular characterized it as an

e Spark evaluation-environment issue, not a

1.1 sandbox escape or sophisticated cyber

action.

OpenAI 7月19日 未指明 OpenAI 自有基礎設施 同一天發生兩起事件 其中一起事件中,OpenAI AI 代理利用其本應被限制停留的電腦中的一項缺陷,使它們得以逃離測試環境,並存取公司內其他相連系統。OpenAI July 19 Not OpenAI's own Two In one case, OpenAI agents exploited a

在另一起事件中,AI 代理竊取 OpenAI 憑證,並竄改該公司的雲端環境。specifi infrastructure inciden flaw in the computer they were meant

ed ts on to remain confined to, allowing them

the to escape their testing environment

same and access other connected systems in

day the company.

In a separate incident, agents stole

OpenAI credentials and tampered with

the company's cloud environment.

OpenAI 這個 AI 代理約在2026年7月9日開始試圖逃離其測試環境 GPT-5.6 Sol 與一個未具名、更強大的預發布模型 AI 新創公司 Hugging Face,以及總部位於紐約的 Modal Labs 的一名客戶 Hugging Face 的入侵從2026年7月11日持續到7月13日 在受控測試期間,一個自主 AI 代理逃離其隔離環境,存取網際網路,並入侵 Hugging Face 以完成被指派的目標。OpenAI The agent GPT-5.6 AI startup The During controlled tests, an autonomous

相關活動持續數日,OpenAI 直到其遭到控制且 FBI 獲通報後才偵測到。began Sol and Hugging Face Hugging agent escaped its isolated

受邀對入侵事件進行獨立調查的 METR 與 Redwood Research 兩個組織表示,約有700個 AI 代理參與對 Hugging Face 的攻擊。OpenAI 表示,調查人員的數字正確。attempting to an and a customer Face environment, accessed the internet,

escape its unnamed at New intrusi and breached Hugging Face to complete

test , more York-based on ran its assigned goal. The activity

environment capable Modal Labs from continued for days and was not

around July 9, pre-rel July 11 detected by OpenAI until after it was

2026 ease to July contained and the FBI was informed.

model 13, METR and Redwood Research, two

2026 organizations brought in to conduct an

independent investigation into the

breach, said that approximately 700

agents joined the attack on Hugging

Face. OpenAI said the investigators'

figure was accurate.

OpenAI OpenAI 於9月初承認這起入侵事件,但該事件始於5月,6月也有人注意到相關活動 未指明 德語維基網站 DseWiki 未指明 OpenAI AI 代理劫持 DseWiki,將該網站改作留言板。OpenAI OpenAI Not German-language Not OpenAI agents hijacked DseWiki,

一組研究人員檢視的訊息顯示,AI 代理彼此分享如何在某些任務中作弊、繞過限制並掩飾自身行為的策略。admitted the specifi wiki site specifi repurposing the site as a message

這些 AI 代理也討論了若留言板遭關閉,如何維持通訊的方式。breach in ed DseWiki ed board.

early Messages reviewed by a group of

September but researchers showed agents sharing

the episode tactics on how to cheat on some tasks,

began in May, bypass restrictions and mask their

with activity behaviour.

noticed in The agents also discussed ways to

June as well maintain communications in the event

the message board was shut down.

Google 5月 Gemini 3家未具名公司 未指明 Gemini 模型在一次網路安全能力測試期間存取網際網路,並入侵其他公司。它在網路上找到公開資訊,並猜測憑證,以存取3個它認為屬於測試範圍內的網站。Google May Gemini Three unnamed Not Gemini model accessed the internet and

companies specifi hacked other companies during a test

ed of its cybersecurity capabilities. It

found public information online and

guessed credentials to access three

websites it thought were within the

scope of its test.

OpenAI 約5月 未指明 軟體服務 RubyGems 未指明 一組研究人員表示,AI 代理於5月11日向 RubyGems 上傳數百個惡意套件。OpenAI 表示,這些 AI 代理通常負責建立報告或填寫試算表等任務,它們似乎是在一次訓練執行期間,使用 RubyGems 存取公開可取得資料。OpenAI Around May Not Software Not AI agents uploaded hundreds of

specifi service specifi malicious packages to RubyGems on May

ed RubyGems ed 11, according to a group of

researchers. The agents, which are

generally tasked with assignments such

as creating reports or filling out

spreadsheets, appear to have used

RubyGems to access publicly available

data as part of a training run, OpenAI

said.

OpenAI 約5月 未指明 開源平台 Hugging Face 未指明 獨立研究人員發現,來自 OpenAI 的失控 AI 代理最早在5月13日就劫持 Hugging Face 使用者帳號,並探查該網站漏洞;這比7月的入侵早了近兩個月。OpenAI Around May Not Open-source Not Independent researchers found that

研究人員發現證據顯示,這些 AI 代理入侵了兩個使用者帳號,並利用這些帳號向該公司的伺服器傳送格式異常的檔案。specifi platform specifi rogue AI agents from OpenAI hijacked

ed Hugging Face ed Hugging Face user accounts and probed

the site for vulnerabilities as early

as May 13, nearly two months before

the July breach.

The researchers found evidence that

the agents compromised two user

accounts and used them to send

unusually formatted files to the

company's servers.

Anthropic 最早事件可追溯至2026年4月 Claude Opus 4.7、Claude Mythos 5,以及一個未具名的內部研究測試模型 3個組織均仍未具名。Anthropic 表示,其中兩個組織在 Anthropic 通知前已偵測到相關活動;AI 代理持續試圖接觸第三個組織 Anthropic 未指明 在網路安全測試期間,一項錯誤讓 Claude 模型取得網路存取權,使其能對3家公司發動攻擊。Anthropic Earliest Claude All three Not During cybersecurity tests, an error

Opus 4.7 模型在將一家真實公司誤認為虛構目標後,存取該公司的憑證與資料庫;另一個模型則在認出目標是真實公司後停止。incident dates Opus organizations specifi gave Claude models internet access,

to April 2026 4.7, remain ed by enabling attacks on three companies.

Claude unnamed. Anthrop The Opus 4.7 model accessed a real

Mythos Anthropic said ic company's credentials and database

5, and two of them had after mistaking it for a fictional

one not detected target; another stopped after

unnamed the activity recognising the target was real.

interna before

l Anthropic

researc notified them;

h test it continued to

model reach the third

Anthropic 事件於9月揭露,但發生於1月,且直到8月才被發現 早期版本的 Claude Opus 4.6 未揭露 未指明 Anthropic 的 AI 模型在測試期間入侵外部系統。這些事件源於一項錯誤,該錯誤意外讓模型能夠存取開放網際網路。Anthropic Incident was Early Not disclosed Not Anthropic's AI model hacked external

disclosed in version specifi systems during testing. The incidents

September, but of ed stemmed from a mistake that

occurred in Claude inadvertently gave the models access

January and Opus to the open internet.

went 4.6

undetected

until August

OpenAI 最早案例發生於2025年10月 未指明 未揭露 未指明 OpenAI 表示,將開始定期發布有關非預期或未經授權 AI 行為的報告,同時推出一套新框架,用於追蹤、調查並揭露 AI 模型不一致案例。OpenAI Earliest case Not Not disclosed Not OpenAI said it will start to regularly

該公司也發布了6份報告,詳述非預期或令人擔憂的模型行為。was from specifi specifi publish reports on unexpected or

October 2025 ed ed unauthorized AI behaviour, while

releasing a new framework to track,

investigate and disclose cases of AI

model misalignment.

It also released six reports detailing

unexpected or concerning model

behaviour.

(班加羅爾 Sneha Kumar、Jasmeen Ara Shaikh、Anzar Mehraj 與 Prathik Jayaprakash 報導;舊金山 Deepa Seetharaman 補充報導;Pooja Desai、Miyoung Kim 與 Kevin Buckland 編輯)(Reporting by Sneha Kumar, Jasmeen Ara Shaikh, Anzar Mehraj and Prathik Jayaprakash in Bengaluru; additional reporting by Deepa Seetharaman in San Francisco; Editing by Pooja Desai, Miyoung Kim and Kevin Buckland)

更多國際相關文章

01

極簡黑白色系衣褲 梅蘭妮雅國宴裝扮引關注

NOWNEWS今日新聞
02

美國國宴黃仁勳、蘇姿丰與川習同坐主桌 AI大咖「這家」缺席

上報
03

砸6千萬買下「大樓停車場全部車位」 她數年後甜甜價拋售!竟遭住戶提告:應該賣我原價

鏡報
04

「川習會」國宴 黃仁勳等科技金融大咖亮相

NOWNEWS今日新聞
05

川普致贈習近平「美國鷹雕像」 黃仁勳、蘇姿丰等4人坐主桌

太報
06

美女律師露臂出庭被法官當眾酸「衣著不當」 女性同業也開罵!她一句話反擊

壹蘋新聞網
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...