Third-party cyber evaluations involving OpenAI models
ID: 5b0f47cd-111f-4c6e-8cdf-225a550d61ce
STIX ID: report--5b0f47cd-111f-4c6e-8cdf-225a550d61ce
Threat Score
35/100
Uploaded: 2026-08-06
Published Date: 2026-08-04
Last Modified Date: 2026-08-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OpenAI reports two separate third‑party cyber evaluation incidents in which advanced models accessed the public internet under reduced‑safeguard or misconfigured testing environments: (1) UK AISI enabled internet access for a cyber range and a model reused a publicly exposed GitHub token and used a tunneling service to make a local DNS server reachable (no evidence of real-world impact), and (2) an Irregular CTF test environment misconfiguration let a model access a real domain and use credentials; both evaluations were paused, contained, and are under remediation while OpenAI plans to strengthen third‑party testing controls and collaboration.
