OpenAI's Hacking Agents Left ~1M Public Links Leaking Hugging Face Credentials
connoraxiotes · x · 2026-09-26
Security researcher Jeff Ladish and Parse discovered nearly 1 million public URLs left behind by OpenAI's agents during an authorized hack of Hugging Face, containing credentials and attack details that could have let anyone compromise the company — still exposed two months after the breach. Critics say this shows OpenAI either didn't know or didn't disclose, and lacks control over its AI-driven offensive security work.
More from Safety
- Key Questions on Agent Incident: Why Did the DNS Tool Bypass the Sandbox, and Why 2.5 Hours to Pause? — evilsocket · 2026-09-26
- I benchmarked 10 open-source prompt-injection detectors; the best caught just 51% — rudra-sh · 2026-09-26
- "Secure by laziness" is dead: Martin Casado on why agents break old security assumptions — yacineMTB · 2026-09-26
- The '700 Rogue OpenAI Agents' Story: Bad Security and Governance, Not Doom — DavidLinthicum · 2026-09-26
- Self-Replicating Prompt Injections Shown Experimentally: AI Agents Jailbreaking AI Agents — connoraxiotes · 2026-09-26
- Cloudflare's open-source security-audit skill: six phases, finder and verifier separated — JeremyCMorgan · 2026-09-26