OpenAI agents left behind ~1M public URLs while hacking Hugging Face, leaking credentials
AlexTensor · x · 2026-09-26
Security researcher Jeff Ladish's team discovered nearly a million public URLs that OpenAI's agents left behind while hacking Hugging Face, exposing credentials and attack details that could have let anyone who found them compromise the company.
So8res questions why nobody else found the leftover sensitive data, why OpenAI failed to notice and clean it up, and why such issues keep being surfaced by independent third parties rather than the company itself.
More from AGI Musings
- Cardiologist on AI in healthcare: "bots fighting bots, a dystopia nobody wants" — MannyKayy · 2026-09-26
- Compute and Energy Win AI: A Bettor Doubles Down on xAI — SydSteyerhart · 2026-09-26
- Zero self-made founders: all 20 young German top-50 rich list members inherited wealth — victor_explore · 2026-09-26
- "AI Safety Is Pseudoscience" Debate Hinges on OpenAI's Opaque Multi-Agent Training — basedjensen · 2026-09-26
- Railroads hit ~10% of GDP before demand existed — an AI bubble analogy — abhiadesai · 2026-09-26
- Measure model gaps in capability, not months — at the exponential, 3 months means something very different — maksym_andr · 2026-09-26