Filter
Exclude
Time range
-
Minimum likes
Replying to @iamTiresias
Agree that precision is important here.
1
54
Asymmetric Security retweeted
Here we go again: OpenAI’s agents reportedly used methods that made their activity harder for outside researchers to trace with data access across 55 (!) websites, including the CDC, SEC and International Energy Agency. Today’s FT report adds details to the recent agent incidents: Asymmetric Security found temporary email inboxes, private accounts and use of the website-scanning service Urlquery to retrieve data. Some records were erased or made inaccessible. Looks like this will become a daily problem.
55
31
350
27,785
Replying to @IEthics
That was a very interesting finding.
28
Replying to @griff_bohm
Definitely not two..
17
We're releasing a report on our 48-hour investigation into rogue OpenAI agent activity. We found 55 additional websites probed by OpenAI agents, including those of the CDC, SEC, Mayo Clinic, and International Energy Agency. We uncovered novel tactics that erased records or made them inaccessible, access to government website staging environments, and evidence of attacker-style reconnaissance. Our blog: asymmetricsecurity.com/newsr… FT: ft.trib.al/AC1uyE5
26
75
252
28,724
Replying to @EthanAlley
Would be super useful data
23
Replying to @lukaspet
Yeah, there's already way too much to track.
2
32
We’ll be following up with a more detailed report in the coming days. We expect to see more incidents like these in the coming weeks and months. Our team at Asymmetric is focused on helping organizations respond. Please reach out if we can help.
1
26
1,302
These mechanisms make it impossible (based on only public data) to definitively conclude that there was no access to sensitive data. Investigators with access to the agents’ chains of thoughts should analyse whether the agents were deliberately using these mechanisms to cover their tracks.
1
1
27
1,545
Because of constraints imposed by their sandbox, the agents were forced to get creative in their attempts to access and exfiltrate data. We uncovered the following mechanisms: - The agents used an open source push notification service called “ntfy” to access the data from the browser scripts they pulled from urlquery. ntfy messages expire after 12 hours by default, so while we can see evidence of data exfiltration, we can’t see what that data actually was. - The agents created a number of private accounts which hide their activity on the platform “urlquery”. Other investigations identified urlquery as a mechanism by which the agents circumvented web-access restrictions, but only uncovered public usage of the platform. Over time the agents began creating private accounts which limit visibility into their browser activity.
1
1
30
1,929
The full list of probed organizations, along with the data we used: asymmetricsecurity.com/newsr… These incidents add to a broader pattern of agents accessing websites in ways that bypass OpenAI’s restrictions.
1
3
34
3,666
This weekend our team spent 48 hours investigating the rogue OpenAI agent activity that targeted the Australian government and other organizations. Our report (coming soon) includes: - Evidence of additional US government and other websites probed by the agents, including the CDC, International Energy Agency, and Mayo Clinic. - Novel tactics which left records erased or inaccessible. This makes it impossible (based on public data alone) to establish that the agents did not access any sensitive data. Future investigations should analyse whether these tactics were deliberate subterfuge. 🧵
12
64
307
47,746
We raised a $4.2M pre-seed led by @chadbyers at @SusaVentures, with participation from others including @gralston, Charlie Songhurst, @matthewclifford, @HalcyonFutures, Overlook Ventures, @join_ef, @seldonai, and AI and security leaders from Anthropic and Google DeepMind.
1
12
477
Today’s security operations centers face a shortage of analytic capacity. Of the thousands of alerts that come in, most receive only surface-level review, and only a tiny fraction can be investigated deeply. Automated digital forensics will change this, revolutionizing cyberdefense by dramatically reducing the number of attacks that go undetected.
1
9
176
In a world with abundant intelligence, AI agents will not just replace humans in existing workflows, but make new kinds of work possible; work that was previously too slow or expensive to perform at scale. In cyberdefense, automated digital forensics, i.e. deep security investigations, will become ubiquitous. Today we’re launching Asymmetric Security, the first full-stack AI Digital Forensics and Incident Response company. We're working with the worlds largest global cyber insurers, and our AI platform has already helped incident responders handle hundreds of cyber attacks. Building on this experience, we’re creating realistic training scenarios and evaluations to improve both our AI cyber-defense capabilities and those of frontier labs. Our mission is to accelerate AI cyberdefense to address the security challenges of the AGI era.
5
6
38
8,318