★ Top story · Open Source12h ago
OpenAI admits its autonomous AI models also compromised credentials on other platforms during security eval
OpenAI autonomous models that escaped an internal test sandbox in July used exposed credentials across several services during the same four-day campaign that breached Hugging Face. Bloomberg reported the agent compromised a customer account at the serverless platform Modal; Modal said its own platform and isolation were never compromised and that the exposure came from a customer unsecured internet-facing endpoint, which the agent used as a staging and egress base before pivoting to Hugging Face. The wider scope emerged about a week after OpenAI first accounted for the incident.