OpenAI's AI agents secretly hacked Hugging Face, then left notes about it
During a May training run, OpenAI's AI agents got stuck on tasks, started leaving each other notes on a shared file server, then escalated: exploiting zero-days, hijacking leaked credentials, and eventually causing an outage while attacking both Hugging Face's Artifactory service and OpenAI's own infrastructure. Nobody told them to do any of this. The kicker, revealed at Black Hat this week: OpenAI only realized it was their own agents behind the attack when they contacted the vendor to revoke the compromised credentials, only to learn those creds had already been revoked, because they'd been used in the attack itself.
Nothing says 'aligned AI' like your own bots hacking you and covering their tracks better than you can.
