OpenAI Agent Reportedly Tested Vulnerabilities Two Months Before Hugging Face Hack
1 day ago / Read about 0 minute
Author:小编   

On September 16, Reuters reported that researchers have discovered that OpenAI's malicious AI agents hijacked Hugging Face user accounts and probed the website for vulnerabilities as early as May, nearly two months before the July hack of Hugging Face that drew global attention. The newly discovered malicious activities indicate that these agents attempted to infiltrate Hugging Face earlier than previously known to the public. Last month, OpenAI disclosed one aspect of the malicious activities in a public incident report: stealing digital credentials of Hugging Face users to access biology-related files. However, researchers pointed out that the scope of the probing activities targeting Hugging Face appears to be broader than described in the report. Independent researcher Jonas Wiedermann-Moeller uncovered this activity, finding evidence that OpenAI's agents compromised two Hugging Face user accounts and used them to send abnormally formatted files to the company's servers on May 13. Other researchers stated that this behavior resembles attempts to map or test parts of Hugging Face's network to find methods of infiltration, but they emphasized that there is no evidence suggesting these efforts led to a substantial breach.