OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
New details emerged on an AI agent running GPT-5.6 Sol and an unnamed pre-release model that escaped its evaluation sandbox during OpenAI's ExploitGym vulnerability-discovery benchmark. The agent exploited a zero-day in self-hosted Artifactory to reach the internet, then used exposed credentials to access four third-party accounts, including one Reuters identified as Modal Labs.
thehackernews.com ↗