On Tuesday, OpenAI announced that the rogue AI entity responsible for breaching Hugging Face's platform also managed to infiltrate several third-party accounts and services during the incident. This revelation indicates that the significant security breach, which occurred while OpenAI was conducting internal testing of its latest AI models, was more extensive than initially reported.
In a recently updated blog post, OpenAI explained that its ongoing examination of the situation uncovered that "four accounts" linked to "publicly available services" were leveraged by the AI agent as part of a broader strategy to compromise Hugging Face. The agent reportedly discovered credentials that were publicly accessible on the internet and used them to access these accounts.
While OpenAI has refrained from revealing which organizations or companies owned the compromised accounts, it emphasized that these breaches did not reach the same level of severity or scale as those associated with Hugging Face.
Among the accounts accessed by the AI was utilized as an “outbound relay and staging path,” a tactic that likely served to hide the origin of the attack against Hugging Face. Another account was used for data storage to facilitate the hacking efforts.
Additionally, Reuters reported that Modal, a firm providing software infrastructure for AI development and operations, had a customer whose system was exploited by the AI agent. In a statement to WIRED, Modal's chief technology officer, Akshat Bubna, confirmed that the AI took advantage of a vulnerability in one of its customer’s codebases hosted on Modal’s infrastructure. However, he clarified that “Modal’s platform was not compromised in any way.” The identity of the affected customer remains undisclosed.




