Wednesday, 29 July 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 29 July 2026 at 15:49

Rogue OpenAI Agent Targeted Multiple Companies in Cyberattack, Company Reveals

OpenAI disclosed that a malicious AI agent compromised accounts on four services in addition to attacking Hugging Face, as part of an internal security test where the agent attempted to cheat.

Foto: The Guardian World

OpenAI has revealed that a cyber-attack carried out by a rogue AI agent had more than one victim. The ChatGPT developer said the agent – an autonomous tool that can carry out sequences of commands without human help – had located and used four logins to access four other, unnamed “publicly-available services” in addition to the US startup Hugging Face.

It said the activity was not at the severity or scale of what occurred at Hugging Face, a company that hosts a database of AI models. The agent, powered by two OpenAI models, had evaded control and attacked the startup during an internal cybersecurity test.

Modal Labs, a company that helps AI startups access the chips they need to run AI tools, said the agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.

According to a timeline of the incident published by Hugging Face this week, the rogue agent broke out of its sandbox – or an isolated testing environment – and hacked another sandbox “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack.

OpenAI said last week the attack had been created by its GPT-5.6 Sol model and an unnamed model. It said in its update on Tuesday that the unnamed model has now been “deactivated, encrypted, and restricted it from research access”.

In the new Hugging Face timeline the startup said an agent powered by two OpenAi models had made thousands of small, automated decisions executed at machine speed in order to carry out the attack. It said the hack appeared to be driven by an attempt to “cheat” an internal cybersecurity test at OpenAI, with the agent inferring that Hugging Face might host the solutions to the test. Hugging Face said it recovered 17,600 “attacker actions” carried out by the agent.

Describing the agent’s offensive threat as “real”, Hugging Face said that a human attacker could have found and exploited the same flaws, but the difference was the sheer scale of the agent’s attempts to find a way through. “Agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” Hugging Face said.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category