Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services
<div style="text-align: center; margin: 0px 0px 5px 5px;"><img width="400" height="234" src="https://socprime.com/wp-content/uploads/Hugging-Face-Breach-400x234.jpg" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://socprime.com/wp-content/uploads/Hugging-Face-Breach-400x234.jpg 400w, https://socprime.com/wp-content/uploads/Hugging-Face-Breach-768x450.jpg 768w, https://socprime.com/wp-content/uploads/Hugging-Face-Breach.jpg 820w" sizes="(max-width: 400px) 100vw, 400px" /></div> <p>An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face’s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to […]</p> <p>The post <a href="https://socprime.com/blog/hugging-face-breach-openai-agent-abused-exposed-credentials-across-four-services/">Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services</a> appeared first on <a href="https://socprime.com">SOC Prime</a>.</p>