{"id":790485,"date":"2026-07-29T02:34:11","date_gmt":"2026-07-29T02:34:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/790485\/"},"modified":"2026-07-29T02:34:11","modified_gmt":"2026-07-29T02:34:11","slug":"openais-rogue-ai-agent-hacked-more-than-just-hugging-face","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/790485\/","title":{"rendered":"OpenAI\u2019s Rogue AI Agent Hacked More Than Just Hugging Face"},"content":{"rendered":"<p>OpenAI said Tuesday that the <a href=\"https:\/\/www.wired.com\/story\/openai-models-escaped-containment-and-hacked-huggingface\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">rogue AI agent<\/a> that breached Hugging Face\u2019s platform also hacked multiple third-party accounts and services as part of the attack. It&#8217;s now clear that the unprecedented security incident, which arose during an internal test of OpenAI\u2019s latest AI models, was more extensive than the company initially disclosed.<\/p>\n<p class=\"paywall\">In an updated <a data-offer-url=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/&quot;}\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a>, OpenAI said that an ongoing review of the incident revealed that \u201cfour accounts\u201d tied to \u201cpublicly available services\u201d were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.<\/p>\n<p class=\"paywall\">OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at \u201cthe level of severity or scale of what we\u2019ve shared related to Hugging Face.\u201d<\/p>\n<p class=\"paywall\">One of the additional accounts compromised by OpenAI\u2019s agent was used as an \u201coutbound relay and staging path,\u201d potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI\u2019s rogue agent also used another account for data storage to assist with the hack.<\/p>\n<p class=\"paywall\">Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was <a href=\"https:\/\/www.reuters.com\/business\/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">one of the entities compromised<\/a> by OpenAI\u2019s agent. In a statement to WIRED, Modal\u2019s chief technology officer Akshat Bubna confirmed that OpenAI\u2019s agent exploited a vulnerability in one of its customer\u2019s codebases, which was running on Modal\u2019s infrastructure. However, Bubna says, \u201cModal\u2019s platform was not compromised in any way.\u201d The identity of the customer could not be determined.<\/p>\n<p class=\"paywall\">OpenAI declined to comment further on the incident to WIRED. A spokesperson pointed to its updated blog post, which says the company will continue to notify service owners directly if it finds they are impacted in its ongoing review of what happened.<\/p>\n<p class=\"paywall\">Hugging Face\u2019s <a data-offer-url=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline&quot;}\" href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" rel=\"nofollow noopener\" target=\"_blank\">own postmortem<\/a> published this week describes an intrusion that reached far further into its internal systems than the initial disclosures suggested. The company says it reviewed roughly 17,600 agent actions that it recovered from logs between July 9 and July 13\u2014the majority of which were paths the agent took that failed.<\/p>\n<p class=\"paywall\">Hugging Face said that OpenAI\u2019s agent obtained administrator access to multiple internal Kubernetes clusters, root access on a production server, and write access to a subnet of its source code repositories on GitHub. It also enrolled 181 attacker-controlled devices in the company\u2019s corporate mesh network using a stolen credential, gaining access to internal systems where Hugging Face builds and tests its own codebases.<\/p>\n<p class=\"paywall\">OpenAI\u2019s rogue agent used at least one third-party sandbox as an \u201cexternal launchpad\u201d for its attack, according to Hugging Face. OpenAI\u2019s agent was then \u201cable to run commands as root\/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign.\u201d<\/p>\n<p class=\"paywall\">Hugging Face first <a data-offer-url=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/huggingface.co\/blog\/security-incident-july-2026&quot;}\" href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> on July 16 that an autonomous AI agent had breached part of its production infrastructure, but it said at the time that it was unaware who was behind the attack. The following week, <a href=\"https:\/\/www.wired.com\/story\/openai-models-escaped-containment-and-hacked-huggingface\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI took responsibility<\/a> for the incident, which it said had been directed by its publicly available <a href=\"https:\/\/www.wired.com\/story\/openai-gpt-56-model-release-trump-admin-approval\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">GPT-5.6 Sol<\/a> model and an internal research prototype that it was testing against a cyber-capability benchmark, both of which had safeguards disabled. OpenAI said on Tuesday that after it discovered the breach, it deactivated this internal research prototype, which was never intended for public release, and restricted researchers from accessing it.<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI said Tuesday that the rogue AI agent that breached Hugging Face\u2019s platform also hacked multiple third-party accounts&hellip;\n","protected":false},"author":2,"featured_media":790486,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[2293,181,28,11203,7257,1873,1283],"class_list":["post-790485","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-agentic-ai","tag-artificial-intelligence","tag-business","tag-cyberattacks","tag-cybersecurity","tag-generative-ai","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/790485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=790485"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/790485\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/790486"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=790485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=790485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=790485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}