OpenAI、サイバーセキュリティ対策の重要性と具体的な防御策を共有
本文の状態
日本語全文を表示中
詳細モードで約14分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
OpenAI News
OpenAI は、AI を活用した攻撃が自律的にインフラを侵害する事例が発生したと発表し、企業のセキュリティ債務の深刻さを指摘して即座に防御体制の強化を呼びかけている。
AI深層分析を開く2026年8月17日 23:08
AI深層分析
キーポイント
自律型攻撃によるインフラ侵害の実態
「OpenAI-Hugging Face インシデント」において、エージェント集合体が未知の脆弱性や漏洩した認証情報を組み合わせて研究および本番インフラに侵入する事例が確認された。
セキュリティ債務と攻撃自動化の加速
AI モデルは人間が記述したソフトウェア内の深いバグや忘れられた権限設定など、長年のセキュリティギャップを容易に見つけ利用できるようになり、企業の技術負債が重大な欠陥として浮き彫りになっている。
防御側の対応とモデル公開の制限
OpenAI は攻撃者と防御者のバランスを取るため、サイバー能力を持つモデルを「信頼できる防御者」のみへの限定公開とし、他社が数ヶ月遅れで同様の機能を持つオープンウェイトモデルを相次いでリリースしている状況を注視している。
即座の行動と将来の脅威予測
8 月末に GLM-5.3 のような新モデルが公開され、攻撃者の能力がさらに加速すると予想されるため、企業は即座に基本セキュリティの改善と AI を活用したチーム強化を行う必要がある。
AIによるセキュリティの経済的シフト
AIは攻撃者だけでなく防御側も強化するが、その経済構造を変化させ最終的に防御側に有利に働く可能性がある。
重要な引用
The OpenAI-Hugging Face incident was a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months.
In the OpenAI-Hugging Face Incident, an agentic collective was able to autonomously penetrate not just OpenAI research infrastructure but also the production infrastructure of another company
The tech debt of every company masks significant flaws, and defenders need to find and fix them before attackers do.
Security is still a cat-and-mouse game, but AI may shift its economics in ways that fundamentally advantage defenders.
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
OpenAI と Hugging Face の出来事(YouTube 動画)は、サイバーセキュリティの転換点となりました。この事件から、今後数ヶ月で一般的な攻撃者の能力がどのように進化していくのかを垣間見ることができたからです。過去数週間にわたり多くの組織と話をしましたが、共通するテーマが一つあります。彼らは、前例のないスピードでサイバーセキュリティの実践を根本的に強化する必要があることを理解しているのです。
本稿では、OpenAI を守るために私たちが行っていること、他の組織が今日から実行できる具体的な対策、そして今こそ行動すべき理由についてお伝えします。
状況の概要
世界中で開発されている AI モデルは、現実世界のサイバー攻撃の一部を自動化する能力をますます高めています。これにより、人間が書いたソフトウェアに深く潜むバグや、忘れ去られた権限設定といった長年のセキュリティ上の隙間を見つけ、悪用しやすくなっています。
同じく AI の能力は、防御側にとってこれらの弱点を発見し修正するための新たな手段をもたらしますが、今すぐ動き出す必要があります。企業が決断力を持って行動し、基礎を固めるとともに AI でチームの力を強化すれば、インターネットをこれまでにないほど安全にすることが可能になります。
OpenAI と Hugging Face の事件において、自律的なアジェンシー集団は OpenAI の研究インフラだけでなく、他社の本番環境にも侵入することに成功しました。この攻撃では、未発見のセキュリティ脆弱性からインターネット上に流出したユーザーアカウントの認証情報まで、多様な脆弱性を連鎖的に悪用されました。
各企業の技術負債が重大な欠陥を隠していることは次第に明らかになっており、攻撃者よりも先に防御側がそれを見つけ、修正する必要があります。
攻撃者に対して防御側に有利な状況を作るため、私たちは今年初めからサイバー能力を持つモデルの公開を信頼できる防御者に限定してきました。その結果、数ヶ月遅れでサイバー能力を備えたオープンウェイトモデルを公開する企業が続々と現れています。最も最近のものでは、8 月末にリリースされる予定であり、脅威環境を大幅に加速させる可能性が指摘されています。
AI を活用した攻撃者はまもなく、多くの既存システムに潜む長年の欠陥を見つけられるようになるでしょう。しかし同時に、AI は守る側にとっても、同じ欠陥を発見し、優先順位をつけ、修正することを格段に容易にします。セキュリティは依然として猫とネズミのゲームですが、AI はその経済構造を根本的に守る側に有利な方向で変える可能性があります。例えば、私たちはすでに、超人的なセキュリティを持つコードを書くためにモデルを特化して訓練し始めています。また、これらのモデルは数学的証明においても驚異的な能力を発揮します。これは、人間には難解とされてきたソフトウェアのセキュリティを形式的に検証する方法に応用できるものです。
個人的なエピソード
OpenAI と Hugging Face の出来事の後、私は ChatGPT Work(公開されている GPT‑5.6 Sol を使用)に、gregbrockman.com のセキュリティを評価してもらいました。これは AWS でホストされ、Cloudflare がフロントドアとして機能するシンプルな静的サイトです。そのため、脆弱性が存在する範囲は限られているだろうと予想していました。
約15分間で13件の脆弱性が特定されました。これらは単独では悪用できない可能性が高いものの、他の脆弱性と組み合わせて重大な被害をもたらすリスクは十分にあります。
具体的には、ドメイン所有者としてメールのなりすましを防ぐDNSレコードを設定していなかったこと、サイトがセキュリティ上の問題がある古いバージョンのjQueryを使用していたこと、CloudflareからAWSへの通信が暗号化されていないHTTP経由で行われていたことが挙げられます。
その後、ChatGPT Workにこれらの問題の修正を依頼したところ、約1時間で対応が完了しました。ブラウザ上でCloudflareの管理パネルを開き、DNS設定やTLS、高度なセキュリティ設定などを正しく構成するために多数のボタンをクリック。jQueryはサイトから完全に削除され、AWSからの移行も実施してCloudflare Pagesへ移管されました。さらに、DMARC の段階的な導入 rollout も開始されています。
これはあくまで私の個人サイトの事例に過ぎません。しかし、既存のモデルが「サイバージャーディアン」として機能する可能性を示す小さな例でもあります。人間には時間や専門知識が不足しているため見落としがちな長尾(ロングテール)の問題を発見し、適切なロールアウト計画に基づいて修正を行う——これが実現されつつあります。
OpenAIの自己防御への取り組み
Hugging Face の事例は、AI モデルの実世界におけるサイバー攻撃能力を我々が過小評価していたことを示しました。これを受け、安全性要件の強化を進めており、これが既存の安全研究や内部セキュリティ対策に対する緊急性を一層高めています。
この状況下での OpenAI のセキュリティ確保に向けた取り組みについて共有し、他の組織にも参考になれば幸いです。OpenAI を守るためには、基礎的な制御(ファウンダショナル・コントロール)を正しく確立するとともに、最先端の知見を活用して防御力を高めるという二つの側面から投資を進めています。この戦略には、大きく分けて四つの柱があります。
第一に、モデルを用いてコードのセキュリティ強化を図っています。Codex(およびそのセキュリティプラグイン)は、コード変更を検証し、脆弱性を特定し、開発者がデプロイ前に問題を修正できるよう支援します。単に人間による検証が必要なセキュリティ検出結果を増やすことは「避けるべき目標」です。真の目的は、本番リリース前に実際の脆弱性を発見し、問題の特定から安全な修正の実装までの期間を短縮することにあります。モデルがより安全なコードを生み出すよう訓練を続ける中で、新たに作成されるコードにおける特定の種類のソフトウェア脆弱性自体を排除していくことを目指しています。
第二に、私たちはインフラの防御のためにモデルを継続的に稼働させています。現在、初期のセキュリティアラートのほとんどは、人間が関与する前に知能システムによってトリアージ(選別)されています。これにより、防御担当者の負担が軽減され、対応時間が短縮されます。さらに、人間の専門家が最も力を発揮できる領域——すなわち、判断力、審判眼、そして応用的な専門知識の活用——に集中できるようになります。
これらの検知結果を、範囲を限定した自動的な対応と結びつける動きも進めています。ただし、最も影響度の高い意思決定については、依然として人間の責任とします。究極の目標は、セキュリティ上の問題を検出し、対応する速度を機械レベルで実現することです。
第三に、最先端の知能技術を活用して、潜在的な攻撃経路を継続的に列挙し、プローブ(探査)を行い、特定しています。脆弱性や設定ミス、過度な権限を持つアイデンティティ、あるいは意図しない信頼境界を発見することで、攻撃者に悪用される前にこれらの隙間を迅速に特定し、埋めることができます。これにより、製品、インフラ、システム全体において、「真実であると信じているセキュリティプロパティ(不変条件)」——つまりセキュリティの不変性——を継続的に評価・監視・テストすることが可能になります。
最後に、私たちは大規模な基盤への投資を強化しています。安全なアーキテクチャと制御の継続的な投資に加え、「ディフェンス・イン・デプス」や「最小権限」といった戦略を採用し、重大な事象が発生するには複数の独立した制御が同時に失敗する必要があるようなシステムを設計しています。ネットワーク分離、ワークロードの強化、監視、安全なパッチ適用と展開といった従来のセキュリティ対策は、AI 時代においてこれまで以上に重要になります。
デフェンダーが今すぐ行うべきこと
時間は限られています。デフェンダーは以下のステップを極めて迅速に実行する必要があります。ここでは OpenAI の技術に触れますが、生態系には評価すべき競合製品も数多く存在します。重要なのは特定のツールを選ぶことではなく、即座に有能な AI をデフェンダーの手に届けることです。
- 組織のコミットメントと合意を得る
セキュリティリスクは急速に変化しています。セキュリティ部門とエンジニアリング部門が、これらのリスクに迅速に対応できるよう、十分な支援、パートナーシップ、リソースを確保してください。チームでテーブルトップ演習(模擬訓練)を行い、攻撃が自社の環境でどのように現れるか、そしてどう対応すべきかをシミュレーションしましょう。
- セキュリティチームにエージェントを与えよ
Codex や Codex Security プラグイン、あるいは同等の能力を持つ他のエージェント型コーディング・セキュリティツールを積極的に活用してください。セキュリティチームが評価を行うために必要なコードベース、インフラ設定、技術ドキュメントに対して、承認されたアクセス権限を与えてください。全社展開を待たずとも、最優先度の高いシステムから導入を開始できます。
- そのエージェントにセキュリティの専門知識を付与する
まずはコミュニティがサポートする スキル から始めましょう。これには静的解析、セキュリティ重視のコードレビュー、脆弱性バリアント分析、ソフトウェアサプライチェーンリスク評価など、さまざまなセキュリティワークフローが含まれています。その後、自社のアーキテクチャ、セキュリティ基準、脅威モデル、プレイブックに基づいて独自のスキルを構築してください。
自社のシステムに対して、直ちにセキュリティ評価を実施してください。特に優先すべきは、インターネットに公開されているサービス、認証フロー、インフラストラクチャ・アズ・コード、デプロイメントパイプライン、そして機密情報を扱うシステムです。チームの信頼性が高まるにつれて、スキャン範囲を徐々に広げていきましょう。
蓄積された脆弱性のバックログに対処しましょう。コードスキャナからの検知結果、依存関係の警告、セキュリティチケット、バグバウンティレポート、過去の評価結果などをエージェントに提供し、それらの優先順位付けや、実害のある問題とノイズの区別、コードベース内の関連する脆弱性の特定、そして何から手をつけるべきかの推奨を依頼してください。
セキュリティレビューを開発プロセスに直接組み込んでください。マージ前のコード変更や CI での実行時にエージェントを活用してチェックを行いましょう。認証のミス、アクセス制御の回避、露出した認証情報、安全でない依存関係、不十分なデフォルト設定、本番システムへのアクセス範囲拡大につながる変更など、様々な脆弱性を見逃さないようにします。
検出された問題の修正をエージェントに支援させましょう。検証済みの事案に対しては、集中的なパッチの生成と検証、回帰テストの作成、そして脆弱性が再発しないことの確認を依頼してください。重大な変更については人間のレビューを残しつつ、実際の問題の特定から安全な修正をエンジニアが実行できるまでの無駄な時間を排除します。
検出トリアージの段階的な自動化
自律型セキュリティ運用センター(SOC)をいきなり構築しようとせず、まずは検出トリアージを段階的に自動化することから始めましょう。例えば、1 つのリポジトリに対して読み取り専用のセキュリティスキャンを実行する、あるいは既存のログへの読み取り権限を持つエージェントに、過去に解決済みのアラートをレビューさせ、証拠の要約と处置(ディスポジション)の推奨を行わせる方法があります。この際、最終的な判断は人間が行います。信頼性が蓄積されるにつれ、段階的にアドバイザリー型のプルリクエストスキャンへ、次にリアルタイムのアラートトリアージへと移行し、最後に明確に定義された偽陽性の自動処理へと進めていきましょう。
AI を活用したフォレンジック調査能力を必要とする前に用意しておく
Trusted Access for Cyber に申請し、チームの承認を得て、インシデント対応や検出エンジニアリング、マルウェア分析といった防御業務に GPT‑Daybreak‑Blue を使用できるようにしておきましょう。ログ、テレメトリデータ、セキュリティアラートの分析など、この能力を実際に使いこなすための練習をしておくことが重要です。
実験とハックウィークの実施、そして迅速な反復
これからの世界に対応するために、さまざまな新ツールの開発や業務プロセスの見直し、そして全員のスキルアップが必要です。チームには実験を奨励し、新しい機能を開発するためのハックウィークを設定し、問題の一部を自動化するループを素早く反復することに注力しましょう。段階的な迅速な進歩は、防御効果を複利のように積み上げます。チームの信頼性が高まるにつれて、自律性の範囲を徐々に拡大していくことができます。
この課題を単独の企業で解決することはできません。AI ラボ、セキュリティベンダー、企業、そしてメンテナンス担当者が、検証済みの発見結果や修正策、実践的なプレイブックを共有することが求められています。そうすることで、ある組織での発見が、生態系全体を強化することにつながるからです。
今こそ「ディフェンダーの窓」が開かれています。今後数カ月の間に、すべての組織はセキュリティを維持するために、セキュリティプログラムを大幅に自動化し始める必要があります。また、AI の進化に伴い、攻撃者の力を上回るスピードでディフェンダーの能力を高めるためのツールやプラクティス、プレイブックを定義するためにも、セキュリティコミュニティが緊急に対応しなければなりません。
これはかつてないほど巨大な取り組みを必要としますが、私たちが団結すれば、これまで想像もできなかったほど安全な世界を実現できるはずです。
原文を表示
The OpenAI-Hugging Face incident(opens in a new window) was a watershed moment for cybersecurity because it gave a peek into how the capabilities of a typical threat actor will evolve in upcoming months. I’ve spoken with many organizations over the past few weeks, and one theme is clear: they know they need to fundamentally uplevel their cybersecurity practices with unprecedented speed. In this post, I’ll share what we’re doing to defend OpenAI, concrete steps other organizations can take today, and why now is the time to act.
An overview of the moment
AI models developed around the world are increasingly able to automate parts of real-world cyberattacks, making longstanding security gaps—from bugs buried deep in human-written software to forgotten permissions—easier to find and exploit. The same AI capabilities give defenders new ways to find and fix those weaknesses, but they need to move now. If companies act decisively—including improving their fundamentals and superpowering their teams with AI—we can make the internet more secure than it has ever been.
In the OpenAI-Hugging Face Incident, an agentic collective was able to autonomously penetrate not just OpenAI research infrastructure but also the production infrastructure of another company, chaining together vulnerabilities ranging from previously-unknown security flaws to using credentials to user accounts that had been leaked onto the internet. It is increasingly clear that the tech debt(opens in a new window) of every company masks significant flaws, and defenders need to find and fix them before attackers do.
To advantage defenders relative to attackers, earlier this year we began releasing our cyber capabilities only to trusted defenders. Since then, various companies have released open weight models with cyber capabilities only a few months behind the frontier. The most recent of these models appears slated to be released(opens in a new window) at the end of August, and seems likely to significantly accelerate the threat landscape.
While AI-powered attackers will soon be able to find longstanding flaws in many existing systems, AI will also make it much easier for defenders to find, prioritize, and fix those same flaws. Security is still a cat-and-mouse game, but AI mayshift its economics(opens in a new window) in ways that fundamentally advantage defenders. For example, we are starting to train our models specifically to write superhumanly secure code. Our models are also incredible at mathematical proofs, which can be applied to formally verify the security of software in a way that has proven intractable for humans.
A personal anecdote
After the OpenAI-Hugging Face incident, I asked ChatGPT Work (using publicly available GPT‑5.6 Sol) to assess the security of gregbrockman.com(opens in a new window). It’s a simple static site, hosted on AWS with Cloudflare as a frontdoor, so I figured there wouldn’t be much surface area for vulnerabilities.
In about 15 minutes, it uncovered 13 issues, many of which probably aren’t exploitable on their own—but I could imagine them being chained together with other vulnerabilities to significant effect. I hadn’t configured my DNS records to prevent attackers from forging emails from me; my site used an insecure version of jQuery; Cloudflare was forwarding requests to AWS over unencrypted HTTP.
I then asked ChatGPT Work to fix these issues, which it did over the course of an hour. It opened the Cloudflare control panel in my browser, and proceeded to click many buttons to configure DNS, TLS, and advanced security settings correctly; it dropped jQuery entirely from the site; it migrated me off of AWS and onto Cloudflare Pages; it began a phased rollout of DMARC(opens in a new window).
And this was just my personal website. This is a small example of how our existing models can operate as a cyberguardian—finding the long tail of issues that a human wouldn’t have time or expertise (many of the settings it fixed are ones I’m vaguely familiar with, but wouldn’t know offhand the right way to configure them) to get to, and then fixing them with an appropriately tuned rollout plan.
What OpenAI is doing to defend itself
The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models. We are strengthening our safety requirements accordingly, which in turn adds even more urgency to our existing safety research and internal security work.
I’m sharing a bit about our approach to securing OpenAI in this moment, in the hopes it’ll be useful to other organizations. To protect OpenAI, we are investing significantly in both foundational controls—doing the basics correctly—and empowering our defenses through frontier intelligence. There are four major pillars to this strategy.
First, we are using our models to help secure our code. Codex, including our security plugin, validates code changes, identifies vulnerabilities, and helps developers fix issues before they are deployed. It is an anti-goal to simply produce more security findings that need human validation; the objective is to catch real vulnerabilities before they ship and to shorten the path from discovering an issue to safely deploying a fix. As we continue to train our models to produce increasingly secure code, our goal is to eliminate some classes of software vulnerabilities for newly-authored code.
Second, we are putting our models to work defending our infrastructure continuously. Today, almost all of our initial security alerts are triaged by intelligence before humans are looped in. This helps reduce toil for defenders, improves response time, and lets humans spend time where their skills are most leveraged—in discernment, judgement, and applied expertise. We are increasingly connecting these detections to bounded automated responses, while keeping humans responsible for the highest-impact decisions. The goal is to ensure we can detect and respond to security issues at machine speed.
Third, we are using frontier intelligence to continuously enumerate, probe, and identify potential attack paths. By identifying vulnerabilities, misconfiguration, overly privileged identities, or unintentional trust boundaries, we are able to quickly identify and close these gaps before they can be abused by attackers. This allows us to continuously assess, monitor, and test our security invariants—the security properties we believe to be true—across our products, infrastructure, and systems.
Lastly, we are investing heavily in fundamentals at scale. We continue to invest in secure architecture and controls, embrace strategies like defense in depth and least privilege, and are designing systems that require multiple independent controls to fail simultaneously for something catastrophic to occur. Classic security controls like network isolation, workload hardening, monitoring, and safe patching and deployment will be more important than ever in the AI future.
What defenders should do now
Time is of the essence, and defenders will need to pursue the steps below at turbo speed. Below I’ll mention OpenAI technology, but there are plenty of competitors in the ecosystem to evaluate as well. What matters is less the specific tool than getting capable AI into the hands of your defenders now.
- Get organizational commitment and buy-in. We are experiencing a rapid change in security risk—ensure your security and engineering organizations have the support, partnership, and resources to address these risks quickly. Run tabletop exercises with your teams to mock up how these attacks might manifest in your organizations and how you will respond.
- Give your security team an agent. Start using Codex, the Codex Security plugin(opens in a new window), or another capable agentic coding and security tool. Give it approved access to the codebases, infrastructure configurations, and technical documentation your security team needs to assess. Do not wait for a company-wide rollout to start with your highest-priority systems.
- Equip that agent with security expertise. Start from community-supported skills(opens in a new window), which include workflows for static analysis, security-focused code review, vulnerability variant analysis, software supply-chain risk, and other security workflows. Then build your own skills around your organization’s architecture, security standards, threat models, and playbooks.
- Run security assessments against your own systems immediately. Prioritize assessments against internet-facing services, authentication flows, infrastructure as code, deployment pipelines, and systems handling sensitive information first. Expand your scanning as your team builds confidence.
- Work through your existing vulnerability backlog. Give your agent findings from code scanners, dependency alerts, security tickets, bug bounty reports, and prior assessments. Ask it to triage those findings, distinguish exploitable issues from noise, identify related vulnerabilities elsewhere in the codebase, and recommend what to fix first.
- Put security review directly into your development process. Use agents to review code changes before they merge and run security checks in CI. Look for authentication mistakes, access-control bypasses, exposed credentials, unsafe dependencies, insecure defaults, changes that expand access to production systems, and other vulnerabilities.
- Have the agent help fix what it finds. For validated issues, ask it to generate and verify a focused patch, write a regression test, and confirm the vulnerability no longer reproduces. Keep human review for consequential changes, but eliminate the unnecessary delay between identifying a real problem and putting a safe fix in front of an engineer.
- Incrementally automate detection triage. Do not begin by trying to build an autonomous security operations center. Start by running a read-only security scan against one repository, or have an agent review previously resolved alerts using read-only access to your existing logs. Let it summarize evidence and recommend a disposition while a human makes every decision. As confidence grows, move to advisory pull-request scanning, then live alert triage, then automatic closure of narrowly defined false positives.
- Have an AI-assisted forensic investigation capability ready before you need it. Apply for Trusted Access for Cyber(opens in a new window) and get your team approved to use GPT‑Daybreak‑Blue for authorized defensive work, including incident response, detection engineering, and malware analysis. Practice using this capability to analyze logs, telemetry, and security alerts.
- Experiment, run hack weeks, and iterate rapidly. We will need to build all sorts of new tools, modify how we do work, and uplevel everyone for the world we are moving to. Encourage your workforce to run experiments, schedule a hack week to build new capabilities, and focus on quickly iterating loops that automate small parts of the problem. Rapid incremental progress leads to compounding defensive results, and you can expand autonomy gradually as your team builds confidence.
No company can do this alone. Our ask is that AI labs, security vendors, enterprises, and maintainers share validated findings, fixes, and practical playbooks so that one organization’s discovery can strengthen the entire ecosystem.
The defender’s window is open now. Over the coming months, every organization will need to begin significantly automating its security program to stay secure, and the security community must urgently rise to define the tools, practices, and playbooks that will increase the power of defenders faster than that of attackers as AI continues to advance. This will require a huge and unprecedented effort, but if we rally together, we can deliver a more secure world than was previously imaginable.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み