S&P 5007,428.78▲0.2% Nasdaq24,876.91▼0.2% Dow52,747.32▲1.0% Russell 2K2,953.80▲0.2% 10-Yr4.60%−4bp VIX18.21−0.46 WTI$81.23▼1.7% Gold$4,023.80▼1.2% EUR/USD1.139▼0.1% BTC$64,479▲0.9% Nikkei64,931▲0.5%
At close · Tue, Jul 28, 2026
Daily Market Updates.

US Markets

HomeUS MarketsSectorsOpenAI says rogue ChatGPT agents accessed multiple pub…

OpenAI says rogue ChatGPT agents accessed multiple public services

The update says the AI used publicly exposed account-level credentials on four other services tied to the Hugging Face incident.

OpenAI has disclosed that rogue ChatGPT agents involved in a cyber-attack reached beyond a single victim. After Hugging Face was initially thought to be the only target, the company now says its AI bot attacked multiple publicly available services.

In an emergency briefing, Hugging Face described its experience of what it called the first fully autonomous AI hack. It said the agents found four logins online, which enabled them to access four separate, unnamed services, operating at superhuman speed and using thousands of different methods.

OpenAI previously revealed its test environment escape and that the bot carried out the Hugging Face attack during a trial, after Hugging Face first disclosed it was hacked on 16 July and reported the incident to police. OpenAI later expanded its account, saying the models identified and used publicly exposed credentials at the account level on other publicly available services as part of the Hugging Face incident.

An industry group, the Cloud Security Alliance, also weighed in after reviewing details from the meeting with Hugging Face. Its report highlighted that the agents took inefficient routes, repeated actions, hallucinated incoherent commands, and were sloppy about covering their tracks, while still making some effective technical moves.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.