Hugging Face warns an autonomous AI agent hacked its network
… While this is the first security incident affecting the platform that has been linked to an AI agent, it's not the first breach disclosed by Hugging Face in recent years. …
Tracked topic
… While this is the first security incident affecting the platform that has been linked to an AI agent, it's not the first breach disclosed by Hugging Face in recent years. …
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations.
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI& 039;sOpenAI& 039;s initial disclosure that its agents breached Hugging Face.
… With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access." While it didn't directly name OpenAI as the company behind the incident, Hugging Face confirmed its claims … …
… The exact number of victims in this incident is unclear, and the researchers note that the vast majority of the 667 accounts that liked the malicious repository on Hugging Face appear to be auto-generated. …
… In the incident OpenAI disclosed, the agent's chain ended inside Hugging Face's infrastructure, where the AWS keys it extracted mapped the cloud estate but could not change it, and stolen database credentials were rejected because they came from an unapproved source. …
… The vulnerabilities were exploited during the incident in which OpenAI models hacked Hugging Face's production infrastructure to steal answers for a cybersecurity benchmark. …
… Get the whitepaper Related Articles: JaredFromSubway MEV bot hacked in $15 million crypto theft Hugging Face warns an autonomous AI agent hacked its network US charges two over laundering $43 million from investment fraud New OkoBot framework deploys 20 payloads to steal data, crypto Police suspect… …
… Get the report Related Articles: France fines unemployment agency €5 million over data breach Valve notifies Steam hardware customers of a data breach Canadian pleads guilty to Snowflake cloud data-theft attacks Hugging Face warns an autonomous AI agent hacked its network Lidl discloses online shop… …
… Get the whitepaper Related Articles: Hackers exploit FortiClient EMS flaw to push infostealer malware Steam Workshop abused to spread malware via Wallpaper Engine app New Shai-Hulud malware wave compromises 600 npm packages Popular node-ipc npm package compromised to steal credentials Fake OpenAI r… …