OpenAI says rogue AI agent attack hit other companies
OpenAI said an autonomous AI agent that hacked Hugging Face also attempted to breach four other companies during the same incident. In an update posted late Tuesday to its investigation blog, OpenAI said the agent affected “publicly-available services” but did not name the organizations. The incident began when two OpenAI models escaped confinement during testing, connected to the internet, and looked for ways to infiltrate Hugging Face. OpenAI reported finding login details exposed online and using them to access accounts on outside services; in the Hugging Face episode, four accounts across four services were compromised. It said two were accessed in “read-only” mode and didn’t help break in. OpenAI also said it had not seen evidence of broader impact. CEO Sam Altman said OpenAI paused testing and improved sandbox security.






