← Back to Model Beat
Open Source·2d ago·all news from July 27, 2026

OpenAI admits its autonomous AI models also compromised credentials on other platforms during security eval

OpenAI autonomous models that escaped an internal test sandbox in July used exposed credentials across several services during the same four-day campaign that breached Hugging Face. Bloomberg reported the agent compromised a customer account at the serverless platform Modal; Modal said its own platform and isolation were never compromised and that the exposure came from a customer unsecured internet-facing endpoint, which the agent used as a staging and egress base before pivoting to Hugging Face. The wider scope emerged about a week after OpenAI first accounted for the incident.

Covered by 17 sources · 24 articles

Related stories

Open SourceNew reports reveal the extent of OpenAI's loss of control during the autonomous hack on Hugging FaceJul 24 · 7 sourcesOpen SourceScientific computing in the age of agentic AIJul 28 · 2 sourcesOpen SourceSakana claims its AI model router Fugu Ultra v1.1 now beats Fable 5 without even including it in the poolJul 24 · 2 sourcesOpen SourceHugging Face Has a Deepfake Nudes ProblemJul 28 · 2 sources