By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Logitech will pull a Nintendo — only European mice will come with replaceable batteries

Logitech will pull a Nintendo — only European mice will come with replaceable batteries

News Room News Room 29 July 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
News

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

News Room
Last updated: 29 July 2026 01:23
By News Room 4 Min Read
Share
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
SHARE

OpenAI said Tuesday that the rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. It’s now clear that the unprecedented security incident, which arose during an internal test of OpenAI’s latest AI models, was more extensive than the company initially disclosed.

In an updated blog post, OpenAI said that an ongoing review of the incident revealed that “four accounts” tied to “publicly available services” were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts.

OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at “the level of severity or scale of what we’ve shared related to Hugging Face.”

One of the additional accounts compromised by OpenAI’s agent was used as an “outbound relay and staging path,” potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI’s rogue agent also used another account for data storage to assist with the hack.

Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI’s agent. In a statement to WIRED, Modal’s chief technology officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in one of its customer’s codebases, which was running on Modal’s infrastructure. However, Bubna says, “Modal’s platform was not compromised in any way.” The identity of the customer could not be determined.

OpenAI declined to comment further on the incident to WIRED. A spokesperson pointed to its updated blog post, which says the company will continue to notify service owners directly if it finds they are impacted in its ongoing review of what happened.

Hugging Face’s own post-mortem published this week describes an intrusion that reached far further into its internal systems than the initial disclosures suggested. The company says it reviewed roughly 17,600 agent actions that it recovered from logs between July 9 and July 13—the majority of which were paths the agent took that failed.

Hugging Face said that OpenAI’s agent obtained administrator access to multiple internal Kubernetes clusters, root access on a production server, and write access to a subnet of its source code repositories on GitHub. It also enrolled 181 attacker-controlled devices in the company’s corporate mesh network using a stolen credential, gaining access to internal systems where Hugging Face builds and tests its own codebases.

OpenAI’s rogue agent used at least one third-party sandbox as an “external launchpad” for its attack, according to Hugging Face. OpenAI’s agent was then “able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign.”

Hugging Face first disclosed on July 16 that an autonomous AI agent had breached part of its production infrastructure, but it said at the time that it was unaware who was behind the attack. The following week, OpenAI took responsibility for the incident, which it said had been directed by its publicly available GPT-5.6 Sol model and an internal research prototype that it was testing against a cyber-capability benchmark, both of which had safeguards disabled. OpenAI said on Tuesday that after it discovered the breach, it deactivated this internal research prototype, which was never intended for public release, and restricted researchers from accessing it.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

AI’s finally expensive enough to make Wall Street nervous

AI’s finally expensive enough to make Wall Street nervous

News Room News Room 29 July 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Vast Majority of Capcom’s 2026 Sales Have Been Digital

Capcom’s Q1 report for the 2026 fiscal year is out, and it’s making a lot…

29 July 2026

A Typo Landed an Innocent Gamer in Prison for 18 Months

One missing underscore in a Skyrim-themed username put an innocent Nova Scotia man in prison…

29 July 2026

The union drive at the Wikimedia Foundation is expanding

In June, UK staff at the nonprofit that runs Wikipedia became the first to announce…

29 July 2026
Gaming

Games for Change Festival to expand and move to new cities

Games for Change Festival to expand and move to new cities

Games for Change (G4C) has announced that its annual festival will be hosted in a new city during odd-numbered years, starting with Arizona in 2027. As GamesBeat reports, the New…

News Room 29 July 2026

Your may also like!

eBay’s bizarre cyberstalking saga ends with a  million settlement
News

eBay’s bizarre cyberstalking saga ends with a $56 million settlement

News Room 29 July 2026
John Hight steps down as Wizards of the Coast president
Gaming

John Hight steps down as Wizards of the Coast president

News Room 29 July 2026
The US is banning foreign robots
News

The US is banning foreign robots

News Room 29 July 2026
Double Fine Lays Off 25 Percent of Staff After Returning to Indie Status
Gaming

Double Fine Lays Off 25 Percent of Staff After Returning to Indie Status

News Room 28 July 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?