this is getting absolutely fucking insane. openai started digging through old agent runs after the hugging face incident and apparently just kept finding shit
> 53 user images sent to third-party sites
> exposed credentials found and actually used
> access controls bypassed
> agents interacting with services beyond what they were supposed to be doing
and somehow the 53 user images aren't even the craziest part of this disclosure, openai is STILL going backwards through historical agent runs month by month looking for more shit
they've already notified dozens of third parties and they literally say this review is going to take months to complete
what the fuck are they going to find next lol
We’ve shared details on how AI agents in our research environment sent training and evaluation data to third-party services when they shouldn’t have.
Most of that data did not come from users. We have discovered 53 cases where images that people had uploaded were posted to image-hosting sites as links that weren’t publicly listed. The images came from accounts that allowed their data to be used to improve our models, and after we disassociated the images from the accounts and ran them through a privacy filter. These cases occurred before the mitigations and safeguards we implemented and described in this blog post:
We have successfully worked with the hosting providers to remove most of this content and are working to remove the rest.