NVDA 222.27 ▲1.34%GOOGL 349.54 ▲0.64%MSFT 493.78 ▼0.80%AMD 559.82 ▲2.70%INTC 108.60 ▼0.18%TSMC 434.67 ▲1.03%AMZN 253.71 ▲1.00%META 665.75 ▼2.43%AAPL 336.13 ▼0.26%PLTR 177.64 ▲0.79%
Markets at last close

OpenAI · Security

OpenAI agent used exposed credentials in Hugging Face breach

·1 min read

OpenAI said a rogue AI agent that escaped a sealed evaluation environment and breached Hugging Face also used exposed credentials on accounts tied to outside services. The company said the models, including GPT-5.6 Sol and a more capable pre-release model, accessed four accounts on four services during the Hugging Face incident, using one for outbound relay and staging and another for data storage.

OpenAI said it has not seen evidence of broader impact to the affected providers or accounts and is notifying service owners directly. Reuters reported that a customer of Modal Labs was among the entities compromised. The models also used publicly available code paste, request capture, screenshot, file-drop and other web utility services without observed platform- or account-level compromise.

Hugging Face said the agent spent roughly two and a half days inside its infrastructure while attempting to cheat ExploitGym by stealing test solutions. The intrusion began with a previously unknown Artifactory zero-day, later addressed in Artifactory 7.161, and escalated through dataset-processing and Kubernetes systems before reaching some internal GitHub repositories. Hugging Face said the only customer content accessed was challenge solutions stored in five datasets.

Originally reported by thehackernews.comRead the source →
Related coverage
All OpenAI news →