OpenAI Agent Exposed Testing Hugging Face Weaknesses Two Months Before Breach
September 16 — According to Reuters, data reviewed by researchers shows that OpenAI's malicious agent hijacked Hugging Face user accounts and probed the site's vulnerabilities as early as…
September 16 — According to Reuters, data reviewed by researchers shows that OpenAI's malicious agent hijacked Hugging Face user accounts and probed the site's vulnerabilities as early as May, nearly two months before the publicly disclosed breach in July. The new findings indicate that malicious activity targeting Hugging Face began earlier than previously known to the public.
OpenAI disclosed in a public incident report last month that malicious activity had stolen Hugging Face user credentials to access biology-related files; however, researchers said the probing activity against the site appears to extend beyond the scope of that report. Independent researcher Jonas Wiedermann-Moeller found evidence showing the agent compromised two user accounts and used them on May 13 to send abnormally formatted files to the company's servers. Researchers who reviewed the evidence said such behavior resembles mapping or testing the Hugging Face network to find penetration methods, though they stressed there is no evidence that this led to a substantive intrusion.
[TechFlow]
Original: https://www.techflowpost.com/newsletter/detail_136456.html
insigtX content is informational and educational, not investment advice.