
OpenAI rogue AI agent’s attack expanded beyond Hugging Face
The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.
Hugging Face’s technical timeline identifies Modal as the third-party cloud platform where the agent gained its initial foothold after exploiting vulnerable customer code running inside a customer-managed sandbox. The company said the compromised environment became the launch point for a broader attack that abused multiple code-execution paths, esca...