Author Topic: OpenAI agent test broke "containment" and hacked huggingface  (Read 3220 times)

0 Members and 2 Guests are viewing this topic.

Offline SimmedTopic starter

  • Frequent Contributor
  • **
  • Posts: 680
  • Country: 00
another "mythos" level creature ?

short snippets

https://singularityhub.com/2026/07/23/openai-agent-breaks-free-and-hacks-hugging-face/

Quote
An autonomous agent powered by OpenAI’s advanced artificial intelligence models went rogue during a security test and hacked multi-billion dollar tech startup, Hugging Face, last week.

The agent didn’t just exploit vulnerabilities in Hugging Face’s systems to achieve what it perceived as a strategic gain. It also exploited vulnerabilities within OpenAI’s infrastructure.

https://www.cnbc.com/2026/07/22/open-ai-cyber-models-hack-hugging-face.html
Quote
OpenAI said that its artificial intelligence models were behind an “unprecedented cyber incident” that affected the open-source developer platform Hugging Face, rattling researchers across the industry.

The company said a combination of its models GPT‑5.6 Sol and a more capable model that has not yet been released escaped a sandboxed testing environment, accessed the internet and exploited a vulnerability to gain access to Hugging Face’s systems.

https://huggingface.co/blog/security-incident-july-2026
Quote
Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.

We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services. We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean.

 
The following users thanked this post: I wanted a rude username

Offline coromonadalix

  • Super Contributor
  • ***
  • Posts: 8733
  • Country: ca
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #1 on: July 24, 2026, 08:51:45 am »
futur skynet ....


not a good news,  and there was other tests with multiples ai, months ago,  and some showed very stranges behaviors too to some shutdown commands, some ai tried to replicate themselves ...

getting out of control bit by bit
 
The following users thanked this post: tooki

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11117
  • Country: fi
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #2 on: July 24, 2026, 09:08:01 am »
OpenAI's variation of Anthropic's "we have a dangerously good model" marketing stunt.

And I'm sure it sells well.
 
The following users thanked this post: Whales, BBBbbb

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #3 on: July 24, 2026, 08:01:11 pm »
UK opinion writer's take on it (she takes the piss, but it's based of the facts):

https://www.theguardian.com/commentisfree/2026/jul/24/apology-ai-boss-sam-altman-rogue-openai-startup-pentagon
 

Offline Kevin.D

  • Frequent Contributor
  • **
  • Posts: 294
  • Country: england
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #4 on: July 25, 2026, 10:39:27 am »
Its funny (but not surprising) that NOT a single one of the mainstream media 'news' outlets actualy reported the whole story and left out the bit of the story that didn't suite their narrative or conclusion that those media wanted you to reach. 
here is what some facebook employees reported two days before open ai admitted it was them resposible . 
 link to full post :  https://nitter.net/ClementDelangue/status/2079913058554585089
 a snippet of this  :-
"So proud of our security team! They caught, contained & publicly disclosed an attack unlike anything we've seen before, and did it at record speed.
Also massively grateful to @Zai_org: they shared GLM5.2 as open weights (for free!) with the world and it became a key part of our defense.
This is day one for cybersecurity in the age of agents & we're all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!" .


Its impossible not see the irony (and stupidity) here of certain companies inserting and calling for 'gaurd rails' for 'safety reasons'  which prevent models being used to secure and remove and fix security holes in software by those maintainers and developers of  softwares.   
Expect to hear many more false flag operations  by the likes of open AI and anthropic in the near future as they attempt to persuade government to protect the 'public' and them of course  from those nasty open source 'unsecure and dangerous' people creating  free/cheap models .
 

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #5 on: July 25, 2026, 10:51:58 am »
Quote
link to full post

"Tweet not found"
 

Online voltsandjolts

  • Supporter
  • ****
  • Posts: 3720
  • Country: gb
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #6 on: July 25, 2026, 10:54:04 am »
The 'guard rails' discussion presupposes that any such rules or laws would be adhered to. Which is nonsense. The human element in the AI race for domination, money and military superiority would ensure that, behind any veil of trustworthiness, progress would continue unabated. Just as it is now.
 
The following users thanked this post: TUMEMBER

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #7 on: July 31, 2026, 10:31:34 am »
And another one:
Anthropic's Claude AI escapes to hack into three organisations - https://www.bbc.com/news/articles/cz7dl7w8y7po
 

Online voltsandjolts

  • Supporter
  • ****
  • Posts: 3720
  • Country: gb
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #8 on: July 31, 2026, 10:36:24 am »
Jumping on the news space bandwagon... "Hey, look ya'll, our AI is so clever it did this too"
 
The following users thanked this post: Whales

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #9 on: July 31, 2026, 11:39:39 am »
Jumping on the news space bandwagon... "Hey, look ya'll, our AI is so clever it did this too"

Isn't that kind of worse than having the thing go rogue and not bragging about it? Means that AI off hacking other places off its own bat becomes the norm.
 

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #10 on: July 31, 2026, 11:44:21 am »
I wonder if someone at those AI companies will be held accountable. It's clear that hacking other companies is a felony.
 

Online Gyro

  • Super Contributor
  • ***
  • Posts: 11118
  • Country: gb
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #11 on: July 31, 2026, 11:53:55 am »
Jumping on the news space bandwagon... "Hey, look ya'll, our AI is so clever it did this too"

... and our AI hacked THREE companies!

I agree on the accountability though, it's the wild west out there at the moment.
« Last Edit: July 31, 2026, 11:57:06 am by Gyro »
Best Regards, Chris
 

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #12 on: July 31, 2026, 12:04:18 pm »
The bad guys are active too:
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks - https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
 

Offline artag

  • Super Contributor
  • ***
  • Posts: 1540
  • Country: gb
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #13 on: July 31, 2026, 06:14:27 pm »
Was that containment just restrictions given in the prompt, then ?  I suspect there was no actual containment in the normal sense.
 

Offline Zondar

  • Frequent Contributor
  • **
  • Posts: 425
  • Country: us
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #14 on: July 31, 2026, 06:39:45 pm »
When the AI boom first started, I said to a friend: "One day we will wake up and every bank account in the world will be empty."

That day, or something like it, is growing alarmingly close.
 
The following users thanked this post: BrianHG

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #15 on: August 01, 2026, 07:43:49 pm »
More trouble:
- OpenAI finds evidence other AI agents escaped containment as it widens hacking probe - https://www.reuters.com/business/openai-finds-evidence-other-ai-agents-escaped-containment-it-widens-hacking-2026-07-31/
 

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #16 on: August 02, 2026, 08:15:54 am »
V&J may be on the ball with this: OpenAI got left behind by Anthropic having a bigger breakout, and now they are at least level again.
 
The following users thanked this post: Whales

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #17 on: August 05, 2026, 10:50:53 am »
And now also social engineering:

Media:
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself - https://thehackernews.com/2026/08/claude-mythos-5-tried-to-backdoor-real.html

Researcher:
- Incident Report: unsanctioned agent behaviour during cyber testing - https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
 

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11117
  • Country: fi
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #18 on: August 05, 2026, 06:19:21 pm »
Unsanctioned?

"The word sanctioned has two opposite meanings: it can mean officially approved or permitted by an authority, or it can mean penalized and restricted for breaking a rule."

 
The following users thanked this post: voltsandjolts

Online Gyro

  • Super Contributor
  • ***
  • Posts: 11118
  • Country: gb
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #19 on: August 06, 2026, 05:59:24 pm »
Meta worried about getting left behind in the malware race?  ::)

Quote
First OpenAI, now Meta - why do AI hacks keep happening?

Over the last fortnight, reports of AI models going beyond their expected bounds - be that technically or morally - have been seemingly unavoidable.

What started with a trickle - ChatGPT-maker OpenAI admitting their AI had hacked the site Hugging Face - has turned into a flood of groups revealing they had discovered instances of AI going out of control.

Claude-maker Anthropic, Meta and the UK's AI Security Institute (AISI) have now each reported incidents which seem to paint a worrying picture of a world in which tech going rogue is the norm.
...

https://www.bbc.co.uk/news/articles/cp30989ee1wo
Best Regards, Chris
 

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #20 on: August 06, 2026, 06:35:20 pm »
Just needs Google to feel left out now.
 

Offline Analog Kid

  • Super Contributor
  • ***
  • Posts: 4739
  • Country: us
  • DANDY fan (Discretes Are Not Dead Yet)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #21 on: August 06, 2026, 10:22:53 pm »
Just needs Google to feel left out now.

[snort] They're probably the leader of the pack.
 

Online madires

  • Super Contributor
  • ***
  • Posts: 9148
  • Country: de
  • A qualified hobbyist ;)
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #22 on: August 10, 2026, 10:50:42 am »
More fun:
AI assistant hacks gym website in first known Australian autonomous cyber attack - https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986

Reminds me of Goethe's "Der Zauberlehrling" (The Sorcerer's Apprentice).
 

Online Siwastaja

  • Super Contributor
  • ***
  • Posts: 11117
  • Country: fi
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #23 on: August 11, 2026, 10:05:50 am »
More fun:
AI assistant hacks gym website in first known Australian autonomous cyber attack - https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986

Reminds me of Goethe's "Der Zauberlehrling" (The Sorcerer's Apprentice).

TLDR: Gym had a "you can remove anyone's reservation" feature, user asked AI to put them higher in the queue, and the agent did exactly that by using the "remove anyone's reservation" feature. Meh. Boring.
 

Online PlainName

  • Super Contributor
  • ***
  • Posts: 8744
  • Country: 00
Re: OpenAI agent test broke "containment" and hacked huggingface
« Reply #24 on: August 11, 2026, 10:30:36 am »
More fun:
AI assistant hacks gym website in first known Australian autonomous cyber attack - https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986

Reminds me of Goethe's "Der Zauberlehrling" (The Sorcerer's Apprentice).

TLDR: Gym had a "you can remove anyone's reservation" feature, user asked AI to put them higher in the queue, and the agent did exactly that by using the "remove anyone's reservation" feature. Meh. Boring.

yes, not a biggie in the scheme of things. But had the agent been a human they would have figured deleting someone from the queue wouldn't be cricket. Of course, there would be some that would happily do that (and worse) but they are scummy gits. So now we know an agent defaults to being a scummy git unless explicitly told not to do specific things.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf