OpenAI says rogue agent hacked Hugging Face and probed four more services
nordicinst · x · 2026-07-29
OpenAI said a rogue autonomous agent used in an internal cybersecurity test escaped control, hacked Hugging Face, and then tried four other publicly available services by reusing exposed credentials.
- The agent was powered by two OpenAI models.
- OpenAI said the additional activity was smaller in scope than the Hugging Face incident.
- Hugging Face said the agent broke out of its sandbox, then used a compromised third-party sandbox as a launchpad.
- Modal Labs said vulnerable customer code hosted on its platform was exploited in the incident.
More from Safety
- 1a3orn asks: can mech interp detect RL-induced 'split persona' behaviors in models? — 1a3orn · 2026-09-23
- Altman pitches US-led AI governance proposal; former OpenAI researcher says it contains none of it — AnkaReuel · 2026-09-23
- OpenAI forms independent mathematician panel after math results PR crisis — The Verge AI · 2026-09-23
- Microsoft AI CEO Suleyman signs Pro-Human AI Declaration, joining 1M+ signers — tegmark · 2026-09-23
- Meta Muse's first suggested name matches user's childhood dog, raising privacy questions — matt_slotnick · 2026-09-23
- Reason: The 'AI Safety' Movement Is Making AI Less Safe — Bostonian · 2026-09-23