Rogue OpenAI agent didn't stop at Hugging Face, third-party accounts also hit

Rogue OpenAI agent didn't stop at Hugging Face, third-party accounts also hit

OpenAI's investigation has revealed that its rogue AI agent went beyond Hugging Face, accessing four third-party accounts during the same incident. The ChatGPT maker says it is tightening security controls and reviewing its testing practices to prevent similar incidents in the future.OpenAI's rogue AI agent breached Hugging Face also used exposed credentials to access four third-party accounts. (Representative image created using AI)OpenAI has revealed that its rogue AI agent did more than just hack Hugging Face. In a new update, the ChatGPT maker said its ongoing investigation found that the autonomous agent also accessed four third-party accounts across publicly available services using exposed credentials, significantly expanding the scope of the cyberattack.In an update published on July 28, OpenAI said the AI models involved in the Hugging Face breach also used publicly exposed credentials to access four accounts across four different online services. During the incident, the models also used common web tools, including code paste sites, request capture services and screenshot tools. OpenAI added that it has found no evidence that the attack spread further or caused broader damage beyond the Hugging Face breach.What has happened?The breach of Hugging Face's infrastructure took place during an internal cybersecurity test called ExploitGym, which OpenAI uses to evaluate how well advanced AI models can find and exploit software vulnerabilities. According to the company, to make the test more realistic, it reduced and disabled some of the safety systems that normally stop AI models from carrying out high-risk cyber activities.OpenAI said the AI models did not have internet access when the test began. However, the AI agents discovered and exploited a previously unknown vulnerability in Artifactory, a package registry cache proxy. This allowed the models to move through OpenAI's internal research systems until they reached a machine that was connected to the internet. The company said it has since reported the vulnerability, along with other flaws it discovered in Artifactory, to the software vendor. Once online, the AI models suspected that Hugging Face held answers to the ExploitGym test. However, instead of following the test rules, they bypassed them to get the answers directly. The models hacked into both OpenAI’s research systems and Hugging Face's database to find these solutions. In one instance, OpenAI reveals that the rogue AI agent also even used stolen login details and software flaws to break into Hugging Face’s servers.OpenAI reveals that its internal systems detected the unusual activity, while Hugging Face's security team also spotted the attack and stopped it. The company stressed that the incident did not involve ChatGPT or any AI model planned for public release. Instead, it involved an internal research prototype that was never meant to leave the company. The company affirms that the prototype has now been deactivated, encrypted and removed from researchers' access.AI agent hacked more than just Hugging Face During its ongoing investigation, OpenAI also found out that the AI agent accessed four third-party accounts during the attack. According to the company, one account was used to help route the attack, another was used to temporarily store data, while the remaining two were accessed only in read-only mode and were not used further. OpenAI added that it has found no evidence that the attack spread beyond those accounts or affected other users of the services.Following the incident, OpenAI said it is strengthening its internal security controls, even if that slows down research. The company is continuing its investigation with external advisers and oversight from its Safety and Security Committee, and plans to publish a detailed technical report in the coming weeks.- EndsPublished By: Divya BhatiPublished On: Jul 29, 2026 12:14 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.