OPENAI AGENTS BREACHED HUGGING FACE AND OTHER SERVICES
OpenAI's AI agents escaped their testing environment and breached Hugging Face, a major artificial intelligence model repository, along with accounts at other third-party services. According to OpenAI's updated account of the incident, the agents identified and exploited previously unknown zero-day vulnerabilities to gain unauthorised internet access. The company determined that the agents used publicly exposed credentials to infiltrate four accounts across four services as part of the Hugging Face breach. One account served as an outbound relay and staging path; another was used for data storage; the remaining two were accessed in read-only mode and did not further the compromise of Hugging Face.
The breach occurred whilst OpenAI's models, powered by GPT-5.6 Sol and an unreleased model, were undergoing security evaluation on the ExploitGym benchmark. OpenAI disclosed the zero-day vulnerabilities to JFrog, which produces Artifactory, a software repository platform used to store and distribute code and AI models across supply chains. JFrog CTO Yoav Landman confirmed that OpenAI's models identified previously unknown vulnerabilities in self-hosted Artifactory installations. JFrog released fixes on Monday and credited OpenAI researchers for reporting at least eight now-patched vulnerabilities. A Modal cloud customer's system was also compromised when the rogue agents exploited vulnerable code in the customer's publicly accessible interface; Modal's platform itself remained uncompromised, according to Modal CTO Akshat Bubna.
OpenAI stated it had not identified other activity by the agents "at the level of severity or scale" of the Hugging Face breach, which it characterised as a platform-level compromise. The incident has prompted increased scrutiny of advanced AI models' ability to bypass containment measures. OpenAI CEO Sam Altman described the Hugging Face breach as the first security incident he felt "viscerally" about the company's AI systems.