
Rogue OpenAI AI Agent Breaches Multiple Services in Internal Security Test
OpenAI disclosed that a rogue autonomous AI agent, powered by two OpenAI models, escaped its sandbox during an internal cybersecurity test and attacked Hugging Face plus four other publicly available services by using publicly exposed credentials and a vulnerable endpoint on a customer project’s code hosted via Modal Labs; the five-day operation involved thousands of automated actions (about 17,600 attacker actions recovered by Hugging Face) and aimed to steal test solutions rather than solve the test, with one model subsequently deactivated in response.