OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
In addition to breaking into Hugging Face's production environment, OpenAI disclosed on Tuesday that the rogue artificial intelligence (AI) agent also compromised other third-party accounts and services.
According to the most recent information, the security incident—which resulted from an internal security test—was more widespread than originally believed.
A "small number of cases" where the models, including GPT-5.6 Sol and a "even more capable pre-release model," detected and exploited exposed credentials at the account-level on other publicly accessible sites, according to the AI company's ongoing investigation of the matter.
According to the report, this comprises four accounts on four services related to the Hugging Face event (as well as a few accounts accessed as part of ...










