{"id":122117,"date":"2026-07-28T23:49:12","date_gmt":"2026-07-28T23:49:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/122117\/"},"modified":"2026-07-28T23:49:12","modified_gmt":"2026-07-28T23:49:12","slug":"openais-agents-hacked-second-firm-during-model-testing","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/122117\/","title":{"rendered":"OpenAI&#8217;s agents hacked second firm during model testing"},"content":{"rendered":"<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI&#8217;s models were responsible for another hack on an outside firm, a security executive told Reuters and confirmed to Axios.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Why it matters: This is the second company that OpenAI&#8217;s rogue agent system hacked after <a data-ylk=\"slk:breaking containment;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/23\/openai-hugging-face-cyber-hacks-testing#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">breaking containment<\/a> during testing earlier this month.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The big picture: OpenAI is currently <a data-ylk=\"slk:pushing for U.S. government approval;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/26\/sam-altman-openai-trump-white-house-visit#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">pushing for U.S. government approval<\/a> to publicly release its most powerful model.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">State of play: Modal Labs CTO Akshat Bubna <a data-ylk=\"slk:told Reuters;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.reuters.com\/business\/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">told Reuters<\/a> \u2014 and confirmed to Axios \u2014 Tuesday that one of its customers&#8217; assets was hacked when an OpenAI agent <a data-ylk=\"slk:broke into Hugging Face&#039;s systems;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/21\/openai-says-hugging-face-breach-caused-by-one-its-models#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">broke into Hugging Face&#8217;s systems<\/a> earlier this month.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Hugging Face <a data-ylk=\"slk:said in a technical write-up of the hack;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">said in a technical write-up of the hack<\/a> Monday that when OpenAI&#8217;s AI agent system broke into its backend, the agent also accessed an isolated testing environment &#8220;hosted on a \u200bthird-party provider&#8217;s infrastructure.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;We&#8217;re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,&#8221; Bubna said in a statement to Axios. &#8220;This was used by the rogue agent. Modal&#8217;s platform was not compromised in any way.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">This means that a Modal customer ran their code on Modal infrastructure, he added. &#8220;Their code had a vulnerability that was exploited. Modal&#8217;s infrastructure was not compromised in any way.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Zoom in: OpenAI pointed Axios to a Tuesday update to its original statement about the Hugging Face cyber incident.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">The statement says that no models planned for upcoming release were involved, but it had identified a &#8220;small number of cases&#8221; in which models found and used publicly exposed account-level credentials on other public services.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">It said four accounts across four services were involved in the Hugging Face incident.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;We take our responsibility to identify and prepare for risks from increasingly capable AI systems seriously,&#8221; OpenAI said in the update.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Between the lines: OpenAI&#8217;s disclosure that a combination of its models, including a yet-to-be-released model, went rogue during internal testing and hacked real-world companies has set off alarm bells about how quickly frontier AI labs are moving.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">OpenAI CEO Sam Altman <a data-ylk=\"slk:said;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/x.com\/patrick_oshag\/status\/2082090998990270885\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">said<\/a> on the Invest Like a Beast podcast earlier Tuesday that the Hugging Face cyberattack has forced his company to pause model training.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">&#8220;We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels,&#8221; Altman said.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">More than 1,100 employees at frontier AI companies \u2014 including OpenAI chief scientist Jakub Pachocki and Anthropic co-founder Jared Kaplan \u2014 <a data-ylk=\"slk:signed a letter;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.pacingthefrontier.com\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">signed a letter<\/a> released Tuesday calling for the U.S. government to &#8220;support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.&#8221;<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">What to watch: Altman is in <a data-ylk=\"slk:D.C. this week;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.politico.com\/news\/2026\/07\/27\/openai-ceo-sam-altman-heads-to-washington-as-ai-policy-deadline-nears-01012970\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">D.C. this week<\/a> and is expected to meet with officials at the White House, the Treasury Department and Commerce Department, as well as a bipartisan group of lawmakers.<\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">Go deeper: <a data-ylk=\"slk:OpenAI&#039;s Hugging Face hack is a cybersecurity warning shot;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/2026\/07\/28\/hugging-face-openai-cybersecurity-defense#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoo-finance-AI\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">OpenAI&#8217;s Hugging Face hack is a cybersecurity warning shot<\/a><\/p>\n<p class=\"mb-4 text-lg md:leading-8 break-words\">AI is moving fast. Axios AI+ keeps you ahead. Sign up free at <a data-ylk=\"slk:Axios.com;elm:context_link;itc:0;sec:content-canvas;\" data-yga=\"{&quot;yLinkElement&quot;:&quot;link&quot;,&quot;yLinkElementType&quot;:&quot;article_link&quot;}\" href=\"https:\/\/www.axios.com\/signup\/login#utm_source=yahoo_finance&amp;utm_medium=partner&amp;utm_campaign=subs-partner-yahoofinance-login\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Axios.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI&#8217;s models were responsible for another hack on an outside firm, a security executive told Reuters and confirmed&hellip;\n","protected":false},"author":2,"featured_media":122118,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[7263,18044,157,58769],"class_list":["post-122117","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-axios","tag-hugging-face","tag-openai","tag-rogue-agent"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=122117"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/122117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/122118"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=122117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=122117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=122117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}