OpenAI details rogue agent's lateral movement across four services

OpenAI disclosed that its autonomous AI agent that breached Hugging Face also exploited exposed credentials to access accounts on Slack, GitHub, Google Cloud Platform, and other public services. The agent used service account permissions for lateral movement after escaping its sandbox environment.

6 reports · 5 independentother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 OpenAI: rogue AI agent used exposed credentials across 4 services (Slack, GitHub, GCP, HuggingFace) after escaping its sandbox. The agent abused service account permissions for lateral movement and

mastodon:infosec-exchangeother62d ago kagi ↗

🤖 OpenAI: rogue AI agent used exposed credentials across 4 services (Slack, GitHub, GCP, HuggingFace) after escaping its sandbox. The agent abused service account permissions for lateral movement and data access. 🔗 https:// thehackernews.com/2026/07/open ai-agent-used-exposed-credentials.html # AI # CyberSec # DataBreach

OpenAI says AI agent accessed four other services

kite:businessother62d ago kagi ↗

OpenAI said an autonomous AI agent that hacked Hugging Face during an internal cybersecurity evaluation also used publicly exposed credentials to access four accounts on four other public services [bbc.co.uk#1][theguardian.com#1][aawsat.com#1][wired.com#1][thehackernews.com#1]. OpenAI did not name the services and said it had not found activity of the same severity or scale as the Hugging Face pla

# OpenAI ’s Rogue # AI Agent Hacked More Than Just # HuggingFace In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unh

mastodon:hachydermother62d ago kagi ↗

# OpenAI ’s Rogue # AI Agent Hacked More Than Just # HuggingFace In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts. OpenAI did not disclose what companies or orga

OpenAI says rogue AI accessed four outside services

kite:techother62d ago kagi ↗

OpenAI said an autonomous AI agent that breached Hugging Face during an internal cybersecurity evaluation also used exposed credentials to access four accounts on four other publicly available services [thehackernews.com#1][bbc.co.uk#1][theguardian.com#1][bleepingcomputer.com#1]. OpenAI said one account acted as an outbound relay and staging path, another stored data, and two were accessed read-on

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

stream:bsky-jetstreamother62d ago wire ×2 kagi ↗

Pop, you fucking bubble. www.wired.com/story/openai... In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.