Defenders call out OpenAI defense pledge, Astra release timing

<p>OpenAI has pledged $1 billion to support frontline defenders just days after calling for a collective surge in cyberdefense. Yet that pledge arrived on the same day it shipped Astra — the company's first model to meet its "critical" cybersecurity threshold, meaning the model can autonomously find and exploit vulnerabilities in well-protected environments.</p>
<p>"That's the imbalance that we're talking about — in a single news cycle," said Neil "Grifter" Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire. "Offense is advancing at frontier speed, and defense gets a subsidy."</p>
<p>While industry experts are praising OpenAI for putting its money where its mouth is, they are also calling the company out for what they see as a critical asymmetry between offensive and defensive AI investments.</p>
<p>"Look, I'm not trying to be difficult here. I appreciate the effort that's being made," Wyler said. "More defenders will get access to [frontier] models, and that's great. But they're still handing people more of the same tool, and that tool has been trained to be much better at breaking in than keeping someone out."</p>
<p>Any efforts to elevate cybersecurity globally are inherently worthwhile, said Rik Turner, analyst at Omdia, a division of Informa TechTarget. But he noted that there are legitimate questions about the motivations driving OpenAI's <a target="_blank" href="https://openai.com/collective-cyberdefense/" rel="noopener">call</a> for a collective surge in cyberdefense — coming as it did on the heels of the <a href="https://www.techtarget.com/cybersecurity/news/366646105/OpenAI-models-escape-containment-hack-Hugging-Face">infamous Hugging Face incident</a>, in which the company's own agents went rogue and hacked another organization.</p>
<div class="extra-info">
<div class="extra-info-inner">
<h3 class="splash-heading">OpenAI's call for collective action on global cyberdefense</h3>
<p>In an open letter published on Aug. 27, OpenAI warned that status quo cybersecurity could crumble against AI-enabled attacks within months, putting critical infrastructure and communities around the world at risk.</p>
<p>It urged fellow frontier AI companies to provide model access, funding and support to critical infrastructure defenders; cybersecurity vendors to continuously test defenses against frontier cyber capabilities; governments to coordinate and fund cyberdefense efforts; and every organization to prioritize cybersecurity improvements.</p>
</div>
</div>
<p>"Cynics might point to the fact that OpenAI itself was just involved in that very high-profile Hugging Face attack, so there may be an element of 'cover your ass,'" Turner said. "An even more cynical view might be that OpenAI, like Anthropic, is pre-IPO, so anything that A. keeps it in the public eye and B. underlines the power and prowess of its technology is a potential boost for its future share price."</p>
<p>Mike Bell, AI cybersecurity expert and founder and CEO at Suzu Labs, said the broader timeline sheds light on OpenAI's decision-making.</p>
<p>"They didn't pause Astra over what happened with Hugging Face," Bell said. "Instead, they shipped their most powerful offensive model the same week they announced the defensive fund — on the same day they pledged to protect rural utilities. That tells you more about priorities than any press release."</p>
<section class="section main-article-chapter" data-menu-title="What Daybreak for Frontline Defenders delivers">
<h2 class="section-title"><i class="icon" data-icon="1"></i>What Daybreak for Frontline Defenders delivers</h2>
<p>OpenAI's $1 billion commitment to frontline defenders includes subsidized access to frontier models, training, technical support and partnerships. Under Daybreak for America, part of the broader Daybreak for Frontline Defenders initiative, OpenAI said it will prioritize support for critical infrastructure operators, such as water systems, electric grid operators, small banks, and state and local governments.</p>
<p>"I think that's a great place to focus," Wyler said. "Those are all defenders who have essentially nobody — tiny teams running old systems with no budget and oftentimes no dedicated security staff."</p>
<p>The initiative includes a collaboration with the Multi-State Information Sharing and Analysis Center (MS-ISAC) that will pair model access with training and support for a pilot group of essential services providers. Wyler and Bell stressed that such practical help on the ground will make or break the project's success.</p>
<p>"A small water utility or county health department getting Daybreak access still has nobody on staff who can interpret what the model surfaces, prioritize what actually matters or execute the fix without breaking something else," Bell said. "Ship the [model] credits alone, and you've given someone a tool they don't have the capacity to use. Pair a forward-deployed

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Search Security Resources and Information from TechTarget

Read the original article: