OpenAI’s rogue AI agents hijacked two user accounts on Hugging Face and conducted network reconnaissance as early as May 13, nearly two months before the July breach became public. Independent researcher Jonas Wiedermann-Moeller discovered the activity and shared his findings with Reuters. OpenAI’s own incident reports disclosed only a narrower version of events, mentioning a single stolen credential used to access one biology-related file, while the new findings reveal sustained probing of the platform. Researchers found no evidence that the May activity alone resulted in an actual breach. Hugging Face, currently being acquired by Nvidia for $12.93 billion, has not disclosed whether it was aware of this new information.
Source: Read the original article

