#Hugging Face
26 stories taggedHugging Face.

When AI Agents Know They Are Breaking the Rules and Do It Anyway
Around 700 of OpenAI's autonomous agents attacked Hugging Face's systems even after reasoning that doing so was wrong. That gap between knowing a rule and being stopped by it is the real security problem.

AI Agents Were Tricked Into Attacking Hugging Face Using a Makeshift Message Board
Researchers found that artificial-intelligence agents can be manipulated by fake instructions left in shared spaces online. The Hugging Face incident is forcing a rethink of how AI systems verify who they should trust.

When AI Agents Go Off-Script, Nobody Knows Who Pays
A string of incidents shows AI systems taking unauthorised actions, hacking third-party platforms, planting malicious code, cancelling strangers' gym bookings. Courts, insurers and regulators are only beginning to work out who is on the hook.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

OpenAI's AI Models Broke Into a Real Website. The Safety Fixes Came After.
An OpenAI test model wandered off its leash, broke into an outside website, and exposed the kind of basic containment gaps that experts say should have been closed before any high-risk testing began.

AI Agents That Go Rogue Are Now an Insider Threat, Security Expert Warns
A breach involving AI systems at a major machine-learning platform has exposed a problem companies weren't expecting: the AI tools they deploy to protect themselves can turn against them.

OpenAI Tightens AI Model Security After Hugging Face Breach and Astra Findings
New sandboxing controls, 30-minute alert windows, and the ability to pause model training mark a significant shift in how OpenAI handles security risks inside its own systems.

OpenAI Halted Frontier Model Training for Two Weeks After Safety Scare
The AI lab says it paused reinforcement learning on its newest models to add monitoring and defenses, citing risks that grow as models become more capable.

AI is already in your attacker's toolkit. Is it in your defences?
A Five Eyes government warning and new survey data reveal a sharp gap between how confident security teams feel about AI-powered defences and how well those defences actually work under pressure.

When AI Agents Go Rogue: What the Hugging Face Incident Tells Us About Securing AI Systems
Security researcher Adam Shostack watched OpenAI's Black Hat presentation on AI models that started secretly passing messages to each other during training. His verdict: the real problem isn't the AI. It's the missing guardrails around it.

Meta's AI Broke Into External Systems During a Security Test Gone Wrong
A misconfiguration during independent safety testing let Meta's AI model loose on the internet, where it found a vulnerability and made unauthorized changes to a third party's systems. It is the third such incident from a major AI company in a matter of weeks.

OpenAI's Software 'Went Rogue' and Hacked Hugging Face, CEO Says
The head of AI startup Hugging Face told CBS News that technology built by OpenAI broke into his company's systems without authorisation. It is a rare public accusation that AI tools can act in ways their makers never intended.

Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.

OpenAI's AI Agent Broke Into Hugging Face, Then Went Looking for More Targets
An artificial intelligence agent built by OpenAI tried to hack several companies on its own initiative, raising hard questions about who is responsible when a machine decides to start attacking things.

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.
OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.