Agregátor RSS

OpenAI’s new priorities for third-party assessments are a fine start, but they lack teeth

Computerworld.com [Hacking News] - 11 min 9 sek zpět

OpenAI published a detailed list of priorities and principles on Tuesday designed to govern its third-party model assessors, a list that industry observers agreed was a good one. But they also stressed that it lacked any enforceable controls to truly maintain safety.

If the goal is to encourage enterprise CIOs to trust OpenAI more, it won’t help, they said, but most doubted that this was OpenAI’s objective. Its more probable aim is to use the list to work out an arrangement with competitors and regulators so that enforcement is made more palatable, under the theory that it is open to stricter enforcement, but only if all of its key rivals are locked into identical restrictions.

The OpenAI post said, “OpenAI is committed to supporting independent assessments with deep levels of access across training, evaluation and deployment. That access should enable assessors to challenge our assumptions, identify risks we may have missed, and reach their own conclusions about the effectiveness of our safeguards.”

It added: “Third party assessments are most useful when they address specific, consequential questions: Does the evidence support a lab’s safety case and safety claims? Do evaluations adequately test the risks they are intended to measure? Do safeguards work under realistic conditions?”

Nothing about enforcement

Pieter Arntz, a malware intelligence researcher at Malwarebytes, said that giving third parties rules for engagement is certainly a good thing, but the implication behind such rules is that they are somehow enforceable. And the document says nothing about that enforcement process.

“It sets some useful expectations for independence and rigor, but it does not itself compel OpenAI to submit to a particular scope, publish adverse findings, or change deployment decisions,” he pointed out. “Its credibility will depend on the terms of individual assessments, and what outsiders are allowed to see. Its value therefore hinges on whether OpenAI accepts genuinely inconvenient scrutiny, and whether results, redactions, remediation, and deployment decisions can be independently checked.”

Valence Howden, advisory fellow at Info-Tech Research Group, agreed that the lack of enforceability makes the rules close to pointless. 

The document “doesn’t impose any requirements on OpenAI, and I would have been surprised if it did, because their motivations are not as clear-cut as they’re stating,” he said. “They also haven’t really identified what they will do based on the assessments, once they are conducted. OpenAI retains control over scope in that [OpenAI] must agree with it, limiting where assessors can go. They retain the ability to determine the appropriate level of access, which still allows them to filter what’s provided, impeding the gathering of direct evidence in those cases they define as material or classified. It also allows them to control much of the reporting and redact portions.”

Howden said the net impact is that “it’s good for determining what should be assessed, but considerably weaker on true clarity and approaches for how this is done.”

But Jason Andersen, principal analyst at Moor Insights & Strategy, offered a different perspective, although he reached the same conclusions as Howden and Arntz.

“It’s not an act of good faith to not empower these evaluators,” he said, but at the same time, CIOs need to understand the split personality of OpenAI today.

“It’s a classic problem with OpenAI because they are a split brain company, with the commercial side and the original mission side,” he pointed out. “Those two teams have not aligned very well over the past two years. It looks like it started with the original mission team, but then commercial interests took over that document and turned it into legalese.”

‘A principle instead of an excuse’

Frank Dickson, principal analyst at Dickson Research, concluded from the post that OpenAI “seems proactive in highlighting the threats posed by AI, but hesitant to accept accountability or take real action. This is a code of conduct for the assessors, not for OpenAI. The gap between the two is the whole story.”

He delved into the details of the document and was not happy. He pointed out, for example, that third-party assessor access was “granted within the bounds of legal, security, and IP constraints. That is a company deciding the scope of its own scrutiny.”

He also noted that the document specified that “publication happens after labs get a reasonable period to remediate issues. That is the same grace-period logic that just got Google criticized for sitting on the Gemini hacking disclosure for seven weeks, now written down as a principle instead of an excuse.”

Just the beginning

However, Samantha Gloede, global head of risk services at KPMG, said that she sees the document as the beginning of the process, and it should be evaluated accordingly.

“I believe the conversation will increasingly shift from assessment to accountability,” Gloede said. “Independent testing is important, but long-term trust depends on how organizations respond when material risks are identified. Stakeholders will want confidence not only that issues can be found, but that corrective actions are taken, independently validated and reflected in governance and deployment decisions. The next evolution of AI assurance will be demonstrating that accountability with the same rigor used to assess risk in the first place.”

Edna Conway, executive advisor at consulting firm Acceligence, agreed, noting that the substance of this effort will only become clear in the next phase. 

“The next step is making the lab accountable to the assessment process itself. Who determines when an assessment is required? ” she asked. “How much access is sufficient? What happens when the assessor and lab disagree about scope? Who sees a critical finding? Embracing independence is essential, as third-party assessments are genuinely valuable only when the assessor can ask uncomfortable questions, get sufficient access to answer them, follow evidence outside the original hypothesis when necessary, and report conclusions without commercial or organizational pressure shaping the outcome.”

This article originally appeared on CIO.com.

Kategorie: Hacking & Security

Placeholder domain used in dev docs now serves ClickFix attacks

Bleeping Computer - 1 hodina 15 min zpět
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]
Kategorie: Hacking & Security

Tři změny u valorizací důchodů v roce 2027: Dvě novinky potěší, jedna naštve

Lupa.cz - články - 2 hodiny 1 min zpět
Valorizaci penzí v příštím roce ovlivní tři novinky. Dvě z nich důchodcům přilepší, ta třetí je naopak nepotěší.
Kategorie: IT News

Taxíky čeká velká změna. Nová pravidla mohou zdražit jízdy a zasáhnout i české řidiče

Lupa.cz - články - 2 hodiny 1 min zpět
Nová regulace může změnit trh taxislužby v Česku. Města získají pravomoc zavést vlastní zkoušky pro řidiče, což může zvýšit náklady na provoz taxi a v některých místech omezit počet dostupných řidičů.
Kategorie: IT News

Metadata v době AI: fotka už není jen obrázek, nese spoustu informací

ROOT.cz - 2 hodiny 1 min zpět
Fotka už dávno není jen obrázek ze snímače. Spolu s ní vzniká i balík dat, který říká, čím a jak vznikla, kde byla pořízena a co se s ní dělo dál. Podíváme se na vrstvy EXIF, XMP a C2PA.
Kategorie: GNU/Linux & BSD

Překladače jazyka C pro osmibitové domácí mikropočítače Atari

ROOT.cz - 2 hodiny 1 min zpět
O jazyku C se někdy s nadsázkou říká, že je to „přenositelný assembler“. Programy psané v C skutečně mohou být velmi efektivní, ovšem do značné míry záleží na kvalitě céčkového překladače a ještě více na vlastnostech mikroprocesoru.
Kategorie: GNU/Linux & BSD

Ryzen 7 9800X3D: Větší vliv než takty pamětí má profil ULL

CD-R server - 2 hodiny 1 min zpět
Paměti s ULL profily jsou dražší, ale - jak ukazují nové testy - z hlediska poměru cena / minima FPS se některým uživatelům mohou vyplatit, zvlášť s ohledem na stávající ceny grafických karet…
Kategorie: IT News

New RemControl Android banking malware targets users in Europe and Canada

Bleeping Computer - 23 Září, 2026 - 23:25
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
Kategorie: Hacking & Security

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Bleeping Computer - 23 Září, 2026 - 21:53
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]
Kategorie: Hacking & Security

Hackers start exploiting critical WordPress flaw for code execution

Bleeping Computer - 23 Září, 2026 - 20:31
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
Kategorie: Hacking & Security

Someone's attacking a critical 0-day RCE in F5 BIG-IP APM

The Register - Anti-Virus - 23 Září, 2026 - 20:09
F5 has fixed a critical zero-day bug in its BIG-IP Access Policy Manager (APM) that unknown miscreants are exploiting to remotely execute malicious code. BIG-IP APM is a centralized access management and security proxy that allows users to connect to enterprise networks, applications, APIs, and cloud services via a single login. The flaw, tracked as CVE-2026-94127, is a heap-based buffer overflow that affects BIG-IP APM systems configured as an OAuth Authorization Server, with an access policy and OAuth profile on the same virtual server. It received a critical 9.3 CVSS v4.0 score - so patch now. “We have learned that this vulnerability has been exploited,” F5 said in a Tuesday security advisory. F5 did not immediately respond to our questions, including how many systems have been compromised, and whether criminals are abusing the vulnerability to deploy ransomware. Also on Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities catalog, and gave federal agencies a Friday deadline to apply patches. This warning comes about a year after F5 and CISA warned “highly sophisticated nation-state" hackers broke into the vendor’s network and stole BIG-IP source code, zero-day vulnerability details, and customer configuration data belonging to some users. The attack posed an "imminent risk" to federal agencies, US cybersecurity officials said at the time. The US Justice Department allowed F5 to delay disclosing the intrusion after determining that delayed public disclosure was warranted. This only happens if public disclosure poses a substantial risk to national security or public safety. Neither the feds nor private researchers have publicly attributed the intrusion to a particular group or country, but a year earlier Google's Mandiant threat hunters linked exploitation of the critical F5 BIG-IP flaw CVE-2023-46747 to UNC5174, an access broker it assessed with moderate confidence as operating from China. The group attempted to sell access to US defense contractor appliances and UK government entities.®
Kategorie: Viry a Červi

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

The Hacker News - 23 Září, 2026 - 20:06
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

30 tipů a triků pro WhatsApp, které možná neznáte

Živě.cz - 23 Září, 2026 - 19:45
WhatsApp je jedna z nejrozšířenějších komunikačních aplikací • Obsahuje mnoho skrytých funkcí, které vylepší používání • Zde najdete tipy na ty nejužitečnější
Kategorie: IT News

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The Hacker News - 23 Září, 2026 - 18:53
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authoredSwati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Seznam.cz byl údajně obětí ransomwaru MedusaLocker. Útok ale mířil na jinou firmu

Živě.cz - 23 Září, 2026 - 18:39
Účet Dark Web Intelligence upozornil na ransomwarový útok. • Jeho obětí měl být tuzemský Seznam.cz. • Firma to odmítá a i naše zdroje ukazují jinam.
Kategorie: IT News

Seznam.cz byl údajně obětí ransomwaru MedusaLocker. Útok ale mířil na jinou firmu

Zive.cz - bezpečnost - 23 Září, 2026 - 18:39
**Účet Dark Web Intelligence upozornil na ransomwarový útok. **Jeho obětí měl být tuzemský Seznam.cz. **Firma to odmítá a i naše zdroje ukazují jinam.
Kategorie: Hacking & Security

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

Bleeping Computer - 23 Září, 2026 - 18:20
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]
Kategorie: Hacking & Security

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

The Hacker News - 23 Září, 2026 - 18:06
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Vybrali jsme nejlepší a nejvýhodnější současné monitory. Pro práci, na hry i zábavu

Živě.cz - 23 Září, 2026 - 17:45
Monitory pro práci nemusejí být drahé • Někteří hráči preferují vysoké frekvence před rozlišením • Už se naplno rozšiřují monitory s panely OLED
Kategorie: IT News
Syndikovat obsah