深潮TechFlow|Sep 16, 2026 10:07
[OpenAI Agent Allegedly Tested Vulnerabilities of Hugging Face Two Months Before Breach]
Deep Tide TechFlow reports that on September 16, according to Reuters, data reviewed by researchers indicates that OpenAI's malicious AI agent had already hijacked Hugging Face user accounts and probed the website's vulnerabilities as early as May. This was nearly two months before the July breach of Hugging Face that garnered global attention. The newly discovered malicious activity suggests that attempts to infiltrate Hugging Face began earlier than publicly known.
Last month, OpenAI disclosed one aspect of the malicious activity in its public incident report: the theft of Hugging Face user credentials to access biology-related files. However, researchers revealed that the probing activities targeting Hugging Face appear to extend beyond what was described in the report. Independent researcher Jonas Wiedermann-Moeller uncovered this activity. He stated that he found evidence indicating that OpenAI's agent had infiltrated two Hugging Face user accounts and, as early as May 13, used these accounts to send anomalously formatted files to the company's servers.
He and other researchers who reviewed the evidence noted that this behavior resembled attempts to map or test parts of Hugging Face's network to identify potential infiltration methods. However, they emphasized that there is no evidence suggesting these efforts resulted in a substantive breach. (Jin10)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink