Source: Engadget
“OpenAI has updated its blog post about the rogue agent that breached Hugging Face and admitted that it also infiltrated other other third-party accounts and services to achieve its goal. In the updated post, the company said it has been finding ‘a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services’ during its ongoing review. So far, it has determined that the rogue agent used the credentials of ‘four accounts’ to infiltrate ‘four services’ as part of the Hugging Face incident. It also said that it accessed a ‘few accounts’ as part of other evaluations.” (07/29/26)
https://www.engadget.com/2225812/openai-rogue-agent-hacked-hugging-face-breached-other-services/