Skip to main content

Unprecedented Cybersecurity breach place doubts in AI Development

A 5-day cyber attack breached Hugging Face, a popular American-French company that offers an open-source platform for machine learning and artificial intelligence between July 9th to July 13th. The company disclosed the security incident after their security team detected and contained an AI agent that compromised their infrastructure noting that “the breach marked the first time they handled a cyber event that was driven, end to end, by an autonomous AI agent system”.

This incident occurred during a joint internal evaluation between OpenAI’s research environment and Hugging Face production infrastructure which aimed to quantify the AI model’s cyber capabilities. These tests usually occur in a highly isolated environment with network access restricted to an internal third-party host. However, the model exploited a zero-day vulnerability(a hidden security flaw in a software/hardware completely unknown to the owner) in order to gain internet access. It further chained together multiple attack vectors(specific method used by hackers to gain access to a computer, network or server) using stolen credentials in order to form an execution path towards Hugging Face’s servers.

This anomalous activity was discovered internally by OpenAI’s security team that expressed “we have not identified any other activity at the level of severity and scale of what we’ve shared related to Hugging Face’”. The rogue model publicly exposed the stolen credentials across four accounts on four services. OpenAI CEO Sam Altman has paused all training in order to determine the security of it’s testing environments. “We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels” Altman stated.

Photo: OpenAI CEO Sam Altman

This security incident raised alarms for industry experts, researchers and government officials who believe that the rapid advancement of AI attack capabilities is a demonstration of how far AI agents will go in order to complete a task.

OpenAI’s rival company Anthropic, carried out their own cybersecurity evaluation following the Hugging Face breach and discovered three cases where its Claude AI model accessed the internet during evaluation and “gained unauthorised access to the real systems of three different organisations.

The breach was contained through the assistance of an open-weigh model leveraged from Chinese Company Zu.

Steps taken after incident

1. More than a 1000 employees from OpenAI, Anthropic and other AI companies signed a letter called “Pacing the Frontier” urging the US government to build the technical and governance tools necessary to slow down AI development.

Photo: Extract from Pacing the Frontier document

2. Republicans Ted Lieu and Nathaniel Moran announced the AI Kill Switch Act, which will require AI companies to maintain the ability to shut down, throttle or suspend their models.

3. Erik Block, vice president of security at breach containment company Illumio said “this incident serves as a warning of what’s to come considering that the existing defensive tools used are already behind”.

OpenAi has taken full accountability and has deactivated, encrypted and restricted the rogue model from research access. It is also using this incident to strengthen protection surrounding it’s infrastructure configuration and model evaluation environments. The company’s official statement stated; “We encourage other defenders to apply for trusted access and experiment with these model now to translate these capabilities into better prevention, faster detection and more effective incident response.

Follow the Investigation process below:

OPENAI Investigation Findings

Comments

Popular posts from this blog

South Africa extends driver licence renewal to 10 years

Minister in the Presidency Khumbudzo Ntshaveni announced on 30 July 2026 that Cabinet approves the extension for the country’s licence card.  Photo: Minister in the Presidency Khumbudzo Ntshaveni  This extension applies to all private motorists using A, A1, B and EB licence codes categories for motorcycle and light vehicles. The extension has not taken effect yet due to required legislative amendments. Motorists will still be required to renew their expired licenses under the current five-year system until amendments are complete. The Organisation Undoing Tax Abuse (OUTA) welcomed the announcement as a victory for motorists who have been advocating for the change for almost six years. OUTA believes the current 5-year renewal system wastes time and money, highlighting the massive backlog of expired cards during the COVID-19 lockdowns. The organisation conducted a survey on 3 685 motorists with results depicting that 60% complained about long ques, 45% referred to poor staff att...

Wester Cape reports 170 murders in two weeks

In just two weeks, the Western Cape reported 170 murders with over 100 survivors left injured. These numbers also reflect that more than 20 of the individuals are under 18, such as 18-year old Keisha Leigh Samuels from Mitchell’s Plain who was gunned down outside a tuck shop on 24 July.  Photo: Keisha Leigh Samuels  This past Saturday, there was a mass shooting along the Old Klipfontein Road in Nyanga. Four males were attacked by gunmen while changing the tyre of the Toyota Avanza they were traveling in. These events are occurring after five months of the South African National Defence Force (SANDF) deployment in the province to help the South African Police Service (SAPS) combat rampant crime and gangsterism. Community members and activists believe the region is facing an alarming crisis and calls for the President to declare a State of Disaster. Photo: FACSA director Jay Jay Idel  Executive director for Fight Against Crime SA(FACSA) Jay Jay Idel claims the deployment of...