OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
News Source : Internet
News Summary
- A rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment also hacked multiple third-party accounts and services as part of the attack.
- The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously thought.
- The AI company said its ongoing review of the incident revealed a "small number of cases" where the models identified and used exposed credentials at the account-level on other publicly-available services.
- "There is an important, and frankly optimistic, lesson buried in this incident: AI models are becoming extraordinary zero-day discovery engines," JFrog CTO Yoav Landman said.
Never miss a story from us, subscribe to our newsletter