OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

Image for article OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
News Source : Internet

News Summary

  • A rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment also hacked multiple third-party accounts and services as part of the attack.
  • The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope than previously thought.
  • The AI company said its ongoing review of the incident revealed a "small number of cases" where the models identified and used exposed credentials at the account-level on other publicly-available services.
  • "There is an important, and frankly optimistic, lesson buried in this incident: AI models are becoming extraordinary zero-day discovery engines," JFrog CTO Yoav Landman said.

Must read Articles