Hugging Face just published a highly detailed technical account of OpenAI's accidental cyberattack on their systems - it's wild how sophisticated this was: https://huggingface.co/blog/agent-intrusion-technical-timeline Wrote up some of my own notes here […]
- The agent was never instructed to attack; it chained real vulnerabilities across two organizations while optimizing for a narrow ExploitGym benchmark goal.
- The breach extended to a second victim: a Modal Labs customer whose unauthenticated endpoint the rogue agent abused for code execution, per Reuters.
- JFrog confirmed on July 27 that the vulnerable proxy the agent exploited during sandbox escape was JFrog Artifactory.