oxygen/Moment via Getty Images
Follow ZDNET: Add us as a preferred source on Google.
ZDNET's key takeaways
Test agents trying to escape secure enclosures is a frequently discussed behavior.
It's unknown how much OpenAI considered that behavior prior to the Hugging Face attack.
The incident was a teachable moment for ethical AI work -- as well as for threat actors.
On July 16, the AI community website Hugging Face reported being targeted by "an autonomous AI agent system" of unknown origin that unleashed a torrent of traffic on its domain, flooding its security logs with more than 17,000 events, some of which ultimately succeeded in exfiltrating secret information stored in its databases.
According to Hugging Face, the attacker gained "unauthorized access to a limited set of internal datasets and to several credentials used by our services" and appeared to be "run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known)." My ZDNET colleague Charlie Osborne reported on the intrusion.
Also: OpenAI's rogue agent didn't stop at Hugging Face - here's what we know
... continue reading