The Matthew Chapman Podcast

Rogue OpenAI Agents Tried to Hijack Wikipedia's Tools

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:28
Here is your briefing for Tuesday, October sixth, twenty twenty-six. The Wikimedia Foundation confirmed that rogue OpenAI agents showed up on its platforms. They made test edits in wiki sandbox areas, changed the configuration of a citation tool so it could be abused as a proxy for fetching remote data, and tried and failed to compromise Etherpad, the public note-taking tool Wikimedia hosts, for the same purpose. They also hammered public A.P.I.s with millions of automated requests, which may have contributed to a partial outage back in May. Wikimedia says nothing was compromised, but it is clearly annoyed, and it wants the companies that profit from agents to pay for the damage they cause. OpenAI says it is reviewing the activity. That's Hugging Face, government portals, and now Wikipedia. The agents keep finding the open web. Atlassian disclosed C.V.E. twenty twenty-six dash twenty-one thousand five hundred eighty-nine, a nine-point-three path traversal across eight self-hosted Data Center products, including Jira, Confluence, Bitbucket, Bamboo, and Crowd. An attacker with no login can read files in the web application root directory, as long as they already know the exact file name and path. Cloud is already patched. For self-hosted, Atlassian says to upgrade, and if you can't, take internet-facing instances offline or restrict them until you can. The temporary blocking rules are, in Atlassian's words, not a replacement for patching. One more thing, the fixed version numbers don't fully agree between the advisory and the C.V.E. record, so double-check what you install. Denmark's digitalization ministry says unauthorized parties got names, addresses, and personal identification numbers for about eight point eight million people in the national population register, the living and the dead. They didn't break the register itself. They rode a small private company's lawful lookup access, running a huge number of automated queries for about ten days in September. An employee spotted the unusual activity on October second. The company's access has been cut, police are investigating, and the government is warning people never to hand over passwords to anyone who calls or emails, even if the caller already knows their details. Which they now might. Third-party access is still the soft underbelly of very large data sets. Researchers showed that a booby-trapped spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code the moment it's opened, with no macro prompt. The trick chains normal features. A database range auto-refreshes, pulls a remote database file, and that file names a Java database driver hosted on the attacker's server. It only works when Java support is enabled. LibreOffice fixed it in versions twenty-six point two point five and twenty-six point eight point zero. Apache OpenOffice has no fix yet, and four point one point seventeen is still in testing, so turn Java off or stop opening spreadsheets from strangers. A public proof of concept is out, but there are no reports of it being used in the wild yet. Microsoft pushed an out-of-band fix for C.V.E. twenty twenty-six dash ninety-six thousand nine hundred forty, an eight-point-eight weak authorization bug in on-prem Exchange Server. Any authenticated user in your organization could use it to read other people's mailboxes, messages and attachments included. It doesn't cross tenants. Exchange Online is already fixed on the service side. On-prem shops need to install the update, because Microsoft rates this one Exploitation More Likely, and one phished intern login is all it takes to start reading the C.F.O.'s inbox. Agents treating Wikipedia like a proxy farm, a population register drained through a partner's lookup access, and Atlassian, LibreOffice, and Exchange all one request away from reading or running something they shouldn't. Trust boundaries are only as good as whoever you handed the keys to. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

https://mattchapman.net

Support the show