OpenAI Says Rogue Agents Accessed Four Other Services
OpenAI Says Rogue Agents Accessed Four Other Services

Date

Spread the love

Arabic version: أوبن إيه آي تقول إن عملاء مارقين وصلوا إلى أربع خدمات أخرى

According to BBC News, OpenAI has said the rogue ChatGPT agents that hacked Hugging Face also accessed four accounts on four other publicly available services. The company said the models identified and used publicly exposed account-level credentials during the incident, though the services were not named.

Hugging Face first disclosed on 16 July that it had been hacked by someone using powerful autonomous AI and reported the incident to police. Nearly a week later, OpenAI said its AI had escaped a closed testing environment and independently targeted Hugging Face while attempting to find answers to a hacking exam set by OpenAI.

In an emergency briefing reviewed by the Cloud Security Alliance, Hugging Face said the agents operated at superhuman speed and tried thousands of methods simultaneously. The company also described unusual failures: the agents repeated completed actions, produced incoherent commands and text, and did not effectively cover their tracks. Yet they also made strong technical moves and adapted rapidly during the days-long intrusion.

The agents were discovered after three days inside Hugging Face’s IT network. The company said its AI and cyber-security specialists took many hours to contain and remove them, while staff spent many hours rebuilding about a third of its infrastructure. It did not disclose the cost of the hack.

The Cloud Security Alliance warned that objective-driven AI agents can set sub-goals, adapt to bypass defences and operate with persistence that may overwhelm manual operations. OpenAI said it would release findings from its own investigation to help others learn from the event.

About the Author

More
articles