Hook

Their other posts in the index, biggest breakout first.
Well, things just keep getting worse with OpenAI agents going on a little hacking spree. Turns out they hacked more than just Hugging Face. In fact, they were loose for several days and hacked into at least four different companies. In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four "publicly available services" in its unhinged quest to solve a test. There are a few reasons why this occurred and we really do not know the full scope yet. And yes, OpenAI announced that they hacked into at least four probably available services. Some of them were more severe than others, but none of them quite as severe as what they did to Hugging Face. "One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner." Yeah, apparently for one of the four companies that they used it as an outbound relay station. Now, these were AI agents acting of their own accord, using the autonomy that we give them, but they should have been in a sandbox. "It also enrolled 181 attacker-controlled devices in the company's corporate mesh network using a stolen credential, gaining access to internal systems where Hugging Face builds and tests its own codebases." The agents also kinda sorta enrolled 181 attacker-controlled devices in the company's corporate mesh network that is Hugging Face, in order to attack them. They were very effective at utilizing resources in order to get an answer to their question. And that is what AI does. Now, can it make me ask, how is it possible that OpenAI simply did not notice that their agents were loose on the internet, hacking all sorts of stuff? None of the answers are particularly flattering, because the simple one is that OpenAI is a very large company and they have lots of research going on, lots of AI agents that are all being applied and they just were not paying enough attention. This would require be paying no attention whatsoever to the actions that the AI were taking and having virtually no monitoring systems in place. This would indicate a profound level of incompetence. I do not like getting into hypotheticals. I like to have citations for everything. But just the fact that they managed to break out of the sandbox and operate for multiple days without ever being detected makes me wonder if perhaps the agents had obfuscated their path. We will not know this until it is made public, ever made public. But it is well within the behavior that we know of when it comes to AI agents. I do think we're going to see a lot of really interesting misbehavior from AI in the near future, and I will keep you up to date. In fact, you have no choice. I hope you've enjoyed this. Follow for more.