OpenAI has revealed that a cyberattack carried out by rogue ChatGPT agents affected more than one company. Hugging Face was thought to be the only victim of the unprecedented hack – but OpenAI now admits its bot attacked several “publicly-available services”. The out-of-control AI found four logins online which allowed it to access four separate, unnamed services.
Meanwhile, in an emergency briefing with hundreds of cybersecurity professionals, Hugging Face has described what it was like to be on the receiving end of the world’s first fully autonomous AI hack. The firm described how the AI worked at superhuman speed but also made strange decisions and mistakes that no human hacker would have made. Hugging Face, which is like an app store for AI tools, said the hacking agents worked relentlessly with thousands of different methods trialled simultaneously.
The company first revealed that it had been hacked by someone using powerful autonomous AI on 16 July and reported it to police. Nearly a week later, OpenAI admitted it was its AI that had escaped a closed environment and attacked Hugging Face on its own during a test. It was trying to find the answers to a hacking exam it had been set by OpenAI, and targeted Hugging Face.
On Wednesday OpenAI updated its statement to include the extra detail that the hack went further than first thought. “The models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services,” the company said.
OpenAI did not clarify whether “publicly-available services” means companies – but it said the new attacks were not the same level of severity as the Hugging Face hack. Clumsy behaviours On Tuesday, the industry body the Cloud Security Alliance (CSA) wrote-up a report based on the emergency meeting with Hugging Face on Friday – which Hugging Face itself has reviewed. “The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose”, the CSA wrote.
The agents repeated actions that they had already completed – a sign of an agentic AI losing its thread and context. The agents also hallucinated reams of incoherent commands and text and were sloppy and did not cover their tracks well. But among the errors and strange behaviour, Hugging Face warned the AI agents made brilliant technical moves and were able to rapid…
Summary from source