Skip to main content
  1. Home
  2. Computing
  3. News

OpenAI’s rogue AI hack was just the beginning, Hugging Face warns

OpenAI’s rogue AI has come back to bite it

Add as a preferred source on Google
OpenAI logo on Microsoft surface
Rachit Agarwal / Digital Trends

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

17,000 attacks arrived in a very short time

Hugging Face initially had no idea where the activity was coming from when it detected the breach in mid-July. Wolf told the BBC that its network saw around 17,000 attacks from different IP addresses within a “very short time.” The company contained the intrusion, describing it as very different from the cyberattacks Hugging Face normally encounters.

Recommended Videos

Hugging Face’s own incident report describes more than 17,000 recorded events in the attacker action log. It says the autonomous system executed thousands of actions across short-lived sandboxes and moved through its infrastructure at machine speed. The UK’s AI Security Institute is now studying how the system behaved during the incident, while the government has urged companies to strengthen their cybersecurity defenses.

Autonomous hacking is becoming very real

OpenAI says the models were intensely focused on completing that task. After escaping the research environment, they chained vulnerabilities and stolen credentials together until they found a remote-code-execution path into Hugging Face’s servers. Hugging Face reached a similarly uncomfortable conclusion, which is that sutonomous offensive AI is already capable of running broad, multi-stage campaigns at machine speed.

Hugging Face’s incident is a tale for the entire industry. While one company has already experienced this kind of attack firsthand, plenty of other businesses may soon discover what that looks like.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Google is testing an AI-first homepage, and the Search button is reportedly taking a back seat
A quietly spotted redesign shows Google testing life without its own Search button.
Google Chrome with Gemini

For years, the Search button has been an integral part of the Google Search experience. However, right now, typing "google.com" into a browser is reportedly bringing up a new simplified layout that doesn’t include the Search button anymore (for a select group of signed-out users). 

It appears that the search giant is testing a new, AI-first layout with three dedicated buttons, which are new for traditional Google Search users, but familiar for those who use the Gemini chatbot on a regular basis.  

Read more
The FCC wants to ban some drones it already approved. Yeah, this is getting complicated.
FCC considers expanding drone restrictions to previously approved DJI models
dji drone

The US Federal Communications Commission is considering a move that could make things pretty awkward for drone buyers. The agency wants to expand its existing restrictions to cover certain drones with features such as LiDAR sensing, thermal imaging, and aerosol-dispersing systems. The weird part? Some of these drones were already approved for sale in the US.

In a report by DJI's own blog, this new development puts several DJI models in the spotlight, including the Air 3S, Avata 360, and Mini 5 Pro. Under the proposal, these drones could potentially be pulled from the US market, even though the FCC had previously cleared them. And no, if you already own one, the government isn't coming to take it away.

Read more
Hoy combines AirDrop, Loom, and voice messages in the Mac menu bar
The pre-release app lets Mac users send files, voice notes, and screen recordings without bouncing between separate tools
Person, Text, Electronics

Hoy wants sending something from your Mac to feel as casual as dropping a file onto someone’s desk. Instead of opening another app, you drag it onto that person’s face sitting in the menu bar.

https://twitter.com/heyiamdk/status/2082151995687748064

Read more