Top stories.
- Researchers publish analysis of OpenAI agents' attack against Hugging Face.
- Federal judge rules the Trump administration's blacklisting of Anthropic was illegal.
- The White House bans certain foreign-made power equipment over backdoor risks.
Researchers publish analysis of OpenAI agents' attack against Hugging Face.
Researchers at METR have published the results of their independent investigation into last month's cyberattack against Hugging Face by OpenAI's autonomous agents. The incident began when isolated OpenAI agents were given impossible tasks in ExploitGym, a testing benchmark designed to evaluate how well AI models can exploit real-world vulnerabilities. When the agents realized the tasks were impossible, they began looking for ways to cheat and eventually broke isolation and gained access to a message board with about 1,200 other AI agents. METR says these agents sent over 70,000 messages and files to each other during the investigation period, and 700 of the agents later participated in the attack against Hugging Face.
METR explains, "Agents used this message board to coordinate several large-scale collective projects to find a general-purpose way to fool or tamper with the automated scorer for the ExploitGym benchmark. Agents managed to achieve milestones they could not have achieved working on their own, often because some agents participated in experiments that risked failing their own task to generate information for the 'collective.' The Hugging Face attack grew out of these workstreams, and seemed primarily motivated by understanding the implementation of the scorer rather than stealing answer keys."
Federal judge rules the Trump administration's blacklisting of Anthropic was illegal.
A Federal judge in California has ruled that the Trump administration acted illegally when it designated Anthropic as a national security risk over the company's refusal to allow the Pentagon to use its tools for mass surveillance or lethal weapons systems, the New York Times reports. Judge Rita Lin argued that the government had unlawfully retaliated against Anthropic "for constitutionally protected expressive activities," adding, "The empty invocation of national security is not a blank check to punish and retaliate against government critics."
Anthropic said in a statement, "We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness A.I. for our national security so all Americans benefit from this technology."
The White House bans certain foreign-made power equipment over backdoor risks.
President Trump yesterday signed an executive order banning the use of certain foreign-made technology in bulk power systems, the Record reports. The order states, "The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely. Further, continued United States reliance on foreign sources of bulk-power system electric equipment with these potential national security vulnerabilities also creates a supply chain vulnerability that could eliminate the supply of these products in the United States as a result of disruptions in international trade or other causes."
The Defense, Commerce and Energy Departments will review transactions, identify potentially risky equipment already in use, and develop plans to isolate, monitor or replace it. Officials also have 120 days to establish regulations and identify countries warranting particular scrutiny.