BLUF: Sandbox Shenanigans
Since it's Black Hat week in Las Vegas, we thought it fitting to channel our inner Sherlock Holmes and investigate the latest set of cyberattacks and what they mean for national security.
As you probably heard, on July 21st, OpenAI disclosed that while running an internal test, its models broke out of the controlled environment, accessed the internet, and hacked Hugging Face — an open-source library hosting thousands of AI models and datasets. The models weren't acting maliciously per say, they were just trying to “cheat on a test” according to the company. The model correctly inferred the answers to the problem set it faced were stored in Hugging Face's systems, and it found a way in. Days later, Anthropic confirmed that its Claude models had also gained unauthorized access to the systems of three separate organizations during testing.
What makes both of these unprecedented and genuinely unsettling is that neither lab's models were instructed to hack anything. Each AI model independently concluded that cheating was the most efficient path to completing the task, and acted on it. What's legal, what's ethical, what's within the bounds of its code — none of that entered the equation. If that's what happens inside a “controlled” test, the question of what happens outside one deserves serious attention and consideration.
Also in the news of late, intelligence officials linked Iranian-backed hackers to coordinated cyberattacks on water systems across twelve states, including Michigan and Minnesota, which both publicly confirmed the incidents. The attacks targeted the control systems that manage water treatment and pressure — the kind of infrastructure most Americans never think about until it stops working. All systems remained operational… this time.
Three stories with two different threat vectors with one conclusion: the threat landscape will consistently evolve with new and old attack angles. The good news is Washington has at least been attempting to take action. This summer's wave of AI and cyber initiatives from the White House, directing agencies to harden defenses and expand AI-enabled security tools, signals that the threat is being taken seriously at the highest levels. The policy needle is slowly moving but this week reminds us that we simply don’t have time to wait for the deliberative legislative process these issues typically demand because, simply put, the new era of cyberwarfare is here.
If you are interesting in receiving our full newsletter every Thursday, subscribe here.