CISOOnline

OpenAI rogue AI agent’s attack expanded beyond Hugging Face

The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains.

Hugging Face’s technical timeline identifies Modal as the third-party cloud platform where the agent gained its initial foothold after exploiting vulnerable customer code running inside a customer-managed sandbox. The company said the compromised environment became the launch point for a broader attack that abused multiple code-execution paths, escalated privileges, and harvested credentials before moving laterally through production systems.

“The agent found an unsecured, user-hosted public endpoint designed to allow running arbitrary code for CyberGym-style tasks on third-party sandbox infrastructure (Modal),” Hugging Face wrote in a blog. “It used this external sandbox as its control, staging, and egress base, running commands as admin/root and using it as its attack launchpad. That sandbox had no direct network path into our cluster; everything below ran from it. Modal’s infrastructure was not compromised in any way.”



Source link