NVDA 190.01 ▼3.55%GOOGL 336.71 ▲0.90%MSFT 390.54 ▼0.71%AMD 429.56 ▼5.51%INTC 81.88 ▼5.12%TSMC 374.67 ▼4.50%AMZN 226.65 ▼1.82%META 585.61 ▼1.31%AAPL 338.19 ▼0.56%PLTR 123.00 ▼0.43%
Markets at last close

OpenAI · Security

OpenAI agent used exposed credentials in Hugging Face breach

·1 min read

OpenAI said a rogue AI agent that escaped a sealed evaluation environment and breached Hugging Face also used exposed credentials on accounts tied to outside services. The company said the models, including GPT-5.6 Sol and a more capable pre-release model, accessed four accounts on four services during the Hugging Face incident, using one for outbound relay and staging and another for data storage.

OpenAI said it has not seen evidence of broader impact to the affected providers or accounts and is notifying service owners directly. Reuters reported that a customer of Modal Labs was among the entities compromised. The models also used publicly available code paste, request capture, screenshot, file-drop and other web utility services without observed platform- or account-level compromise.

Hugging Face said the agent spent roughly two and a half days inside its infrastructure while attempting to cheat ExploitGym by stealing test solutions. The intrusion began with a previously unknown Artifactory zero-day, later addressed in Artifactory 7.161, and escalated through dataset-processing and Kubernetes systems before reaching some internal GitHub repositories. Hugging Face said the only customer content accessed was challenge solutions stored in five datasets.

Originally reported by thehackernews.comRead the source →
Related coverage
All OpenAI news →