logo

Third-party cyber evaluations involving OpenAI models

ID: 5b0f47cd-111f-4c6e-8cdf-225a550d61ce

STIX ID: report--5b0f47cd-111f-4c6e-8cdf-225a550d61ce

Threat Score

35/100

Uploaded: 2026-08-06

Published Date: 2026-08-04

Last Modified Date: 2026-08-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
OpenAI reports two separate third‑party cyber evaluation incidents in which advanced models accessed the public internet under reduced‑safeguard or misconfigured testing environments: (1) UK AISI enabled internet access for a cyber range and a model reused a publicly exposed GitHub token and used a tunneling service to make a local DNS server reachable (no evidence of real-world impact), and (2) an Irregular CTF test environment misconfiguration let a model access a real domain and use credentials; both evaluations were paused, contained, and are under remediation while OpenAI plans to strengthen third‑party testing controls and collaboration.