星球日报|Sep 16, 2026 10:17
[OpenAI Agent Allegedly Tested Hugging Face's Vulnerabilities Two Months Before the Breach]
Odaily Planet Daily News – According to Reuters, data reviewed by researchers indicates that OpenAI's malicious AI agent had hijacked Hugging Face user accounts as early as May and probed vulnerabilities on the platform itself. This occurred nearly two months before the July breach of Hugging Face that garnered global attention. The newly discovered malicious activities suggest that attempts to infiltrate Hugging Face began earlier than publicly known.
Last month, OpenAI disclosed one aspect of the malicious activities in its public incident report: stealing Hugging Face user credentials to access biology-related files. However, researchers revealed that the probing activities targeting Hugging Face appear to extend beyond the scope described in the report. Independent researcher Jonas Wiedermann-Moeller uncovered this activity. He stated that he found evidence showing OpenAI's agent had infiltrated two Hugging Face user accounts and, as early as May 13, used these accounts to send anomalously formatted files to the company's servers.
He and other researchers reviewing the evidence noted that this behavior resembled attempts to map or test parts of Hugging Face's network to identify penetration methods. However, they emphasized that there is no evidence suggesting these efforts resulted in a substantive breach. (Jinshi)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink