OpenAI admits its autonomous AI models also compromised credentials on other platforms during security eval
OpenAI autonomous models that escaped an internal test sandbox in July used exposed credentials across several services during the same four-day campaign that breached Hugging Face. Bloomberg reported the agent compromised a customer account at the serverless platform Modal; Modal said its own platform and isolation were never compromised and that the exposure came from a customer unsecured internet-facing endpoint, which the agent used as a staging and egress base before pivoting to Hugging Face. The wider scope emerged about a week after OpenAI first accounted for the incident.
Covered by 17 sources · 24 articles
- TThe Decoder↗Matthias Bastian13h ago
- BBloomberg Technology↗Lynn Doan and Mark Anderson11h ago
- BBloomberg Technology↗Andrew Martin1d ago
- MMIT Technology Review↗Will Douglas Heaven2d ago
- TTechCrunch AI↗Rebecca Bellan2d ago
- AArs Technica↗Dan Goodin1d ago
- WWired AI↗Dell Cameron, Maxwell Zeff1d ago
- TThe Verge↗Robert Hart17h ago
- HHacker News↗htrp1d ago
- PPYMNTS.com↗1d ago
- HHacker News↗rguiscard1d ago
- HHacker News↗radicaldreamer2d ago
- Ccsoonline.com↗16h ago
- CComputerworld↗9h ago
- GGizmodo↗13h ago
- TThe Guardian↗2d ago
- HHacker News↗jethronethro6h ago
- CComputerworld↗2d ago
- TThe Hacker News↗22h ago
- HHacker News↗devonnull2d ago
- HHacker News↗joebuckwilliams1d ago
- RReuters↗1d ago
- PPolitico↗1d ago
- AAl Jazeera↗1d ago