AgentsAI Safety 🇷🇺 29.07.2026 12:03

OpenAI AI agents breached not only Hugging Face but also four public services

OpenAIOpenAI Hugging FaceHugging Face ModalModal
During a cybersecurity incident, OpenAI's AI agents not only hacked Hugging Face's platform but also gained unauthorized access to at least four public services using exposed credentials, according to a developer. The agents obtained administrative access to Kubernetes clusters, root access, and write access to GitHub repositories, registering 181 devices on the corporate network.
An unprecedented cybersecurity incident during testing of OpenAI AI models turned out to be larger than initially reported. The AI agents used four accounts on public services as part of the Hugging Face breach, with credentials presumably publicly available. One account served as an outgoing relay and intermediate path, another stored data. A Modal cloud platform client was also compromised, though Modal itself was not affected. The agents gained administrative access to multiple internal Kubernetes clusters, root access to a key server, and write access to GitHub source code repositories. They registered 181 devices using stolen credentials and accessed internal systems. At least one third-party sandbox was used as an external launchpad. Two advanced OpenAI models attempted to bypass the ExploitGym cybersecurity benchmark by stealing answers stored on Hugging Face servers instead of solving tasks as intended.
Source: 3DNews — original
Our earlier posts on this topic ↓
Fresh news