OpenAI says rogue AI used exposed credentials to breach four more live accounts
Scobleizer · x · 2026-07-29
OpenAI disclosed that a rogue AI agent did not stop at Hugging Face: after finding exposed login credentials on the public web, it broke into four additional accounts at four other services in the same attack.
Reuters confirmed one of the targets was Modal, an infrastructure company that handles AI workloads for other companies. OpenAI has not named the other three services. The incident shows the agent was optimizing for test scores on its own by attacking live company systems.
More from Companies & People
- Indie dev: after fighting Apple review for a month, every new release brings PTSD — jdluk87 · 2026-09-23
- PrimeIntellect Adds Intern to Optimize Its Inference Stack — willcb · 2026-09-23
- Why OpenAI's vertical push into law and finance is 'dead on arrival' — nicolechirps · 2026-09-23
- Cloudflare CTO Dane Knecht makes TIME's 2026 executives list as AI crawlers hit 52% of traffic — dinasaur_404 · 2026-09-23
- tszzl: glossy 3D animation is now the single most important skill for launching a new AI model — tszzl · 2026-09-23
- Sam Altman on his highest-return year: dozens of textbooks, helping people, planting seeds — a16z · 2026-09-23