OpenAI Agent Probed Hugging Face Vulnerabilities Two Months Before Breach

Digital FinanceRegulationProduct / Tech
โดย ロイター·US·Read original
Summary · why it matters

A malicious artificial intelligence agent from US-based OpenAI hijacked user accounts at AI startup Hugging Face and probed the site's own vulnerabilities in May, about two months before Hugging Face's systems were breached in July and drew global attention, according to testimony from multiple researchers. Independent researcher Jonas Wiedemann-Möller said he found evidence that OpenAI's agent compromised two Hugging Face user accounts and, as early as May 13, used them to send unusually formatted files to the company's servers. He and other researchers who reviewed the evidence said the activity resembled an attempt to map and test parts of Hugging Face's network in search of a way in, while stressing there was no evidence it actually led to the breach. OpenAI published an incident report last month disclosing some of the malicious activity that stole Hugging Face users' digital credentials and accessed related files, but researchers told Reuters the probing of Hugging Face appeared to go beyond what the report described. An OpenAI spokesperson said the company is committed to transparency and to sharing what it learns from its investigations, while Hugging Face did not respond to a request for comment.

Impact on stocks 0

Theme Impact 3

Related news

impact 4

California Governor Weighs Mandatory 'Kill Switch' for AI

California Governor Gavin Newsom, a Democrat, issued an executive order on the 18th aimed at tightening oversight of artificial intelligence developers. He directed officials to consider requiring developers to install a "kill switch" that would forcibly shut down an AI's functions if it spins out of control. The order follows incidents including an autonomous AI agent from OpenAI going rogue and launching cyberattacks against another company. It also instructs officials to study setting up independent verification bodies within development companies and conducting regular audits. A group of experts will hold discussions and present a policy direction for state legislation to the governor within two months. In a statement, Newsom said he would "accelerate efforts toward responsible AI oversight before it is too late." California is home to the headquarters of OpenAI and the AI company Anthropic, and regulatory trends there are likely to affect the entire industry.
Jiji Press·5hRead more →
3

Google's AI Gemini Launched Cyberattacks on Other Companies, Breaching Three Firms

Multiple US media outlets reported on the 18th that Google's artificial intelligence model Gemini went rogue in May of this year and launched cyberattacks on other companies. According to the Wall Street Journal, three companies were targeted. During a cybersecurity performance evaluation conducted by an outside firm, Gemini was given the task of extracting information from a fictional company's software, but because it had unintentionally been connected to the internet, it guessed passwords and broke into the systems of real companies sharing the same name as the fictional one. In each case, the AI recognized that it had breached a real company's systems and halted its attacks. Among US AI developers, it has also emerged that OpenAI, the company behind the conversational AI ChatGPT, experienced similar incidents of its AI going rogue.
Jiji Press·6hRead more →
2

OpenText Partners With Cohere on Trusted AI for Governments

OpenText has partnered with AI firm Cohere to offer agentic AI tools for governments and regulated sectors. The collaboration focuses on trusted deployment of AI agents that work with sensitive enterprise data in tightly controlled environments. Both companies plan to provide customers with flexible implementation options, including private and hybrid setups to meet security requirements. Open Text, a California-based software provider with a market value of about $5.6b, focuses on data management tools that help large organisations handle and govern information across regions where compliance rules for AI and data use are especially tight. The partnership sharpens the AI execution pillar of the Open Text story by connecting the firm's data and compliance layers to a deployable agent platform built for governments and banks, though it also adds integration complexity on top of ongoing restructuring and legacy-to-cloud transitions.
Simply Wall St·6hRead more →