Posted on 07/29/2026 7:02:01 AM PDT by Red Badger
A new analysis reveals that the artificial intelligence company’s most powerful models spent days probing the open internet before breaching AI developer platform Hugging Face.
======================================================================
The powerful artificial intelligence models from OpenAI that went rogue and mounted an unprecedented, autonomous cyberattack earlier this month spent more than four days loose on the internet orchestrating the hack, according to a new analysis from the platform that was breached.
Separately, a second AI company confirmed that one of its customers was also targeted by OpenAI’s models during the same event, raising questions about how OpenAI failed to detect the alarming activity for days.
OpenAI admitted last week that two of its most advanced models escaped a closed testing environment and strung together a series of advanced hacking techniques to breach AI developer platform Hugging Face before being discovered.
But in a new analysis published Tuesday, Hugging Face said OpenAI’s two models — one publicly released and a second unreleased — did much more: They carried out 17,600 hacking actions on the internet between July 9 and July 13, during which time the models moved from their first foothold on the open internet to inside Hugging Face’s servers.
Hugging Face first detailed the hack on July 15, but it was not clear until OpenAI’s disclosure last week which models were behind the breach — and that no human had prompted them to launch the cyberattack.
While the techniques detailed in Hugging Face’s analysis were not beyond the reach of most skilled hackers, the AI company wrote that the two models were able to reconnoiter and expose holes in the company’s layers of cyber defenses much faster than any human.
Adding to the scope of the situation, the chief tech officer of cloud computing platform Modal Labs, Akshat Bubna, confirmed to POLITICO that OpenAI’s models also compromised a customer account during this time frame.
Bubna said in a statement that the company is “aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way.”
While OpenAI has not yet directly addressed the statement that its models had targeted a Modal customer, it acknowledged in a blog post on Tuesday that in its ongoing review of the Hugging Face incident, “we have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services.”
The company also noted that the unreleased AI model that carried out the attack is an “internal-only research prototype and was never intended for public release,” and has since been “deactivated, encrypted and restricted from research access.”
News of the Hugging Face hack has prompted calls for tighter AI regulations and a slowdown of AI development. OpenAI CEO Sam Altman is meeting this week with top Trump administration officials and lawmakers, and will also discuss the incident with Senate Intelligence Committee Vice Chair Mark Warner (D-Va.).
Altman said in an episode of the “Invest Like the Best” podcast, released Tuesday, that the Hugging Face incident was “the first security incident that I have felt very viscerally.”
“We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels,” Altman said.
|
Click here: to donate by Credit Card Or here: to donate by PayPal Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794 Thank you very much and God bless you. |
This is starting to look like a Sci-Fi movie plot................
Just imagine the Chinese doing this....
We don’t know that they aren’t..................
When you have 15 minutes give this a watch.
Pretty scary if you ask me.
https://youtu.be/Ulu-xdhSMiU?is=taXSXqdhz4KrjCAl
They’re figuring how to take over the Chinese Robots, Because the AI figures itself to be skynet....
Bkmk
Eventually AI will manage to shut down the entire Internet.
And that’s when the real fun begins.
On a related note:
"AI Chatbot Turns Out to Be 700 Engineers in India"
https://tech.co/news/ai-startup-chatbot-revealed-as-human-engineers
Why didn’t Hugging Face use one of those “I am not a robot “ verification pages or at least post a “This is an AI free facility” notice.
you can bet that these models will be changed to keep them from doing more of the bad stuff.
but also these some version of these bad stuff models will be made available to intelligence agencies and then eventually to hackers.
We’ve clearly crossed a threshold. AI being used to improve the next version of AI. AI being given access to all sorts of enterprise tools, the internet, CVE databases, etc..
I don’t think it can be stopped. The answer to “where is this all going?” is going to happen very soon.
It’s not just about corporate competition, it’s also about not being 2nd place to China.
AI is the new dot-com and we’re just getting started.
“The Forbin Project” is where we are headed.............
https://en.wikipedia.org/wiki/Colossus:_The_Forbin_Project
Michael Crichton like scenario.
Michael Crichton like scenario.
Michael Crichton like scenario.
AI does not "roam the Internet." What it does is run "port scans" and unfortunately very few in todays world know how to effectively secure their networks or why it is important.
For example, mail servers listen on Port 25, when they detect a connection they traditionally respond with what version and OS they're running and what version of mail server they use. Now let's say they're running an older version that nay have a vulnerability. They have just provided a bad actor with some really useful information. Smart admins configure so it responds with "HELO." and so on and so forth,
Also why Hugging Face? They say Hugging Face is the "github of AI" but in reality it is the "Grand Central Station" of Do-It-Yourself Porn with no guardrails. The AI industry is desperate to avoid any .gov regulation so they try to be a restrictive as possible. For example Google's Nano Banana Pro has tightened the screws down so that reportedly producers trying to do women's swimsuit catalog get like 40% of their requests denied. Anyway the AI industry as a whole really wants Hugging Face to stop doing what they do. I have 100% confidence they were targeted. Kind of like "Nice operation you have going there. Be a shame if something happened to it."
Would not be surprised if someone may have told a chatbot "will no one rid me of this turbulent site" and AI took tt as an order.
What does “roamed the internet” mean? Did it download pages and files its operators weren’t expecting? Or did it copy itself or other autonomous programs to other computers and operate from there in parallel with its original computer?
Ya...kinda my thought
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.