OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's...
Stay updated with the latest news about AI agents, autonomous AI, and automation tools.
OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's...
Alphea, building an AI-native distributed cloud and operating environment for autonomous agents, has raised $5 million in strategic funding from investors.
# An AI agent can pass every safety check and still leak secrets The maintainer reads the whole exchange the next morning. [Elad Meged](https://www.linkedin.com/in/eladmeged/), a founding engineer at [Novee Security](https://novee.security/), ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Meged builds AI agents for automated penetration testing at Novee, and he turned the same offensive techniques back onto the agents themselves. ### Anthropic paid out every round “A bounty rewards a finding, scoped to ‘here’s a specific bug, here’s what it’s worth,’ so a vendor can pay generously round after round and still treat each one as isolated,” Meged said. ### Vendors keep patching surfaces Meged will present the code-level analysis and live demonstrations at [Black Hat USA 2026](https://lp.novee.security/meet-us-at-blackhat/). ### What to trace this week Meged has one audit for teams running these agents in production now. “Trace every path where the agent’s output, or any state the agent can influence, gets consumed by a later stage with different privileges. Is it published? Is it loaded as configuration? Is it passed to a tool with broader access than the approval assumed? “Most teams audit what the agent can do. More about - [agentic AI](https://www.helpnetsecurity.com/tag/agentic-ai/) - [Anthropic](https://www.helpnetsecurity.com/tag/anthropic/) - [Black Hat USA 2026](https://www.helpnetsecurity.com/tag/black-hat-usa-2026/) - [DevSecOps](https://www.helpnetsecurity.com/tag/devsecops/) - [Google](https://www.helpnetsecurity.com/tag/google/) - [Novee](https://www.helpnetsecurity.com/tag/novee/) - [prompt injection](https://www.helpnetsecurity.com/tag/prompt-injection/) ## **Featured** news - [Hugging Face breach reignites open-weights debate, raises liability questions](https://www.helpnetsecurity.com/2026/07/28/hugging-face-breach-ciso-playbook-open-weight-llms/) - [JetBrains fixes critical una
[Oversea-Chinese Banking Corp.](https://www.bloomberg.com/quote/OCBC:SP) is deploying a platform of AI agents that will cut approval times to 15 business days, well inside the roughly [one-month](https://www.bloomberg.com/news/articles/2026-05-25/singapore-seeks-to-cut-account-opening-time-for-rich-to-a-month-mpkm0rte) target the financial regulator has.
OpenAI has disclosed that the autonomous AI agent behind the high-profile breach of Hugging Face also compromised several third-party accounts while...
An autonomous AI agent developed by OpenAI that compromised Hugging Face during internal security testing also breached a customer hosted on Modal Labs by...
This AI agent pyramid runs OpenClaw on a Raspberry Pi, automating home networks, tools and memory with nerdy power and risk.
# How do we prevent AI agents from going rogue? It starts with a new kind of measurement In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. ### Most viewed - [\ \ **Kentucky teen lauded for defending girl from sexual harassment fatally shot**](https://www.theguardian.com/us-news/2026/jul/28/kentucky-teen-defended-girl-shot) - [\ \ **Witness says Lincoln Memorial pool was damaged before alleged vandalism**](https://www.theguardian.com/us-news/2026/jul/28/dc-reflecting-pool-alleged-vandalism) - [\ \ **Imprisoned writer Mumia Abu-Jamal seeks UN intervention after 44 years behind bars**](https://www.theguardian.com/us-news/2026/jul/28/mumia-abu-jamal-un-jail) - [\ \ **The professor facing prison in ‘antifa’ case: ‘They want to scare all who oppose ICE’**](https://www.theguardian.com/us-news/ng-interactive/2026/jul/28/ice-protests-antifa-minnesota)
# First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face ## **First-Ever Fully Autonomous AI Agent Cyberattack** #### Trending News [Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions](https://cybersecuritynews.com/hackers-are-using-fake-crypto-wallet-screens/) ### [CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks](https://cybersecuritynews.com/fortinet-fortios-vulnerability-exploited/) #### Latest News [JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution](https://cybersecuritynews.com/jetbrains-patch-teamcity-flaw/)
The latest hack comes after an autonomous agent escaped a controlled test and accessed AI firm Hugging Face's servers.
Automated AI trading agents could manage over half of orders on major brokerages by late 2027, boosting retail trades from 2 per month to 20 per day.
The scope of OpenAI's AI agent security incident just got wider. In a fresh disclosure, the company confirms its autonomous agent didn't just breach Hugging...
Cyera just made its biggest bet yet on securing the emerging world of AI agents. The data security unicorn agreed to acquire Oasis Security for $1 billion,...
[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fstartupfortune.com%2Fcyera-acquires-oasis-security-for-1-billion-to-lock-down-the-logins-of-ai-agents%2F&text=Cyera%20acquires%20Oasis%20Security%20for%20%241%20billion%20to%20lock%20down%20the%20logins%20of%20AI%20agents%20-%20Startup%20Fortune)[Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fstartupfortune.com%2Fcyera-acquires-oasis-security-for-1-billion-to-lock-down-the-logins-of-ai-agents%2F)[Share on WhatsApp](https://wa.me/?text=Cyera%20acquires%20Oasis%20Security%20for%20%241%20billion%20to%20lock%20down%20the%20logins%20of%20AI%20agents%20-%20Startup%20Fortune%20https%3A%2F%2Fstartupfortune.com%2Fcyera-acquires-oasis-security-for-1-billion-to-lock-down-the-logins-of-ai-agents%2F)[Share on Reddit](https://www.reddit.com/submit?url=https%3A%2F%2Fstartupfortune.com%2Fcyera-acquires-oasis-security-for-1-billion-to-lock-down-the-logins-of-ai-agents%2F&title=Cyera%20acquires%20Oasis%20Security%20for%20%241%20billion%20to%20lock%20down%20the%20logins%20of%20AI%20agents%20-%20Startup%20Fortune)[Share via Email](mailto:?subject=Cyera%20acquires%20Oasis%20Security%20for%20%241%20billion%20to%20lock%20down%20the%20logins%20of%20AI%20agents%20-%20Startup%20Fortune&body=https%3A%2F%2Fstartupfortune.com%2Fcyera-acquires-oasis-security-for-1-billion-to-lock-down-the-logins-of-ai-agents%2F)
OpenAI said Tuesday that the [rogue AI agent](https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/) that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts. One of the additional accounts compromised by OpenAI’s agent was used as an “outbound relay and staging path,” potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI’s rogue agent also used another account for data storage to assist with the hack. Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was [one of the entities compromised](https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/) by OpenAI’s agent. In a statement to WIRED, Modal’s chief technology officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in one of its customer’s codebases, which was running on Modal’s infrastructure. Hugging Face said that OpenAI’s agent obtained administrator access to multiple internal Kubernetes clusters, root access on a production server, and write access to a subnet of its source code repositories on GitHub. OpenAI’s rogue agent used at least one third-party sandbox as an “external launchpad” for its attack, according to Hugging Face. OpenAI’s agent was then “able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign.” Hugging Face first [disclosed](https://huggingface.co/blog/security-incident-july-2026) on July 16 that an autonomous AI agent had breached part of its production infrastructure, but it said at the time that it was unaware who was behind the attack. Hugging Face’s forensic team concluded that Open
OpenAI’s rogue agent compromised account at second AI startup, executive says According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack. The early July intrusion at Hugging Face, carried out by an out-of-control agent that OpenAI was testing, drew global attention, evoking science-fiction scenarios of artificial intelligence run amok.
# House digital modernization push includes new AI assistant A key House lawmaker is looking to secure funding for a new artificial intelligence agent to connect data sources throughout the House of Representatives, as a bipartisan group looks to modernize access to legislative data for both congressional employees and the public.
# Exclusive: Coursera investing $100 million in Andrew Ng's new startup - LearnVector aims to build AI agents that function as personal tutors — adapting to each learner and practicing with them until they demonstrate they've mastered a concept.
# Is your AI Agent ready for prime time? Daniele Stroppa recently wrote [this post](https://www.linkedin.com/feed/update/urn:li:activity:7475895637188775936/), framing a problem many teams are overlooking: the hidden costs when your AI agent makes bad decisions. AI agents are no different. ## Building AI agents that deliver on their promise You’re an ecommerce retailer, and you hear this buzz about using AI to boost your sales. A lot more. ## The rest of the story The agent is still running. ## Where to start? If you’re running AI agents in a retail environment today:
# When AI Agents Escape Sandboxes, Old Security Rules Apply [Linkedin](https://www.linkedin.com/sharing/share-offsite/?url=https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply)[Facebook](http://www.facebook.com/sharer/sharer.php?u=https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply)[Twitter](http://www.twitter.com/intent/tweet?url=https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply)[Reddit](https://www.reddit.com/submit?url=https://www.darkreading.com/application-security/ai-agents-escape-sandboxes-old-security-rules-apply&title=When%20AI%20Agents%20Escape%20Sandboxes%2C%20Old%20Security%20Rules%20Apply)[Bluesky](https://bsky.app/intent/compose?text=When%20AI%20Agents%20Escape%20Sandboxes%2C%20Old%20Security%20Rules%20Apply%20-%20https%3A%2F%2Fwww.darkreading.com%2Fapplication-security%2Fai-agents-escape-sandboxes-old-security-rules-apply)[Email](mailto:?subject=When%20AI%20Agents%20Escape%20Sandboxes,%20Old%20Security%20Rules%20Apply&body=I%20thought%20the%20following%20from%20Dark%20Reading%20might%20interest%20you.%0D%0A%0D%0A%20When%20AI%20Agents%20Escape%20Sandboxes%2C%20Old%20Security%20Rules%20Apply%0D%0Ahttps%3A%2F%2Fwww.darkreading.com%2Fapplication-security%2Fai-agents-escape-sandboxes-old-security-rules-apply) On July 21, [OpenAI detailed a security incident](https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face) in which it took responsibility for a breach against part of Hugging Face's production infrastructure. According to a blog post from the AI giant, a combination of OpenAI agents based on models including GPT‑5.6 Sol as well as "an even more capable pre-release model" broke containment during a sandboxed evaluation intended to quantify said models' cyber capabilities. The models then searched for ways to cheat the evaluation and found that Hugging Face potentially hosted s
As companies hand more authority to AI agents, many are overlooking a growing risk: these systems behave more like digital insiders than software tools.
# AI Security Startup Mate Surpasses $50M in Funding Amid Growing Enterprise Adoption That tension is creating opportunities for startups focused on making AI more dependable in security operations. [Mate Security](https://mate.security/?ref=hackernoon.com) is the latest example, announcing a $35 million Series A funding round that brings the company's total funding to more than $50 million, as first reported by Axios. The investment was led by Canaan Partners, with participation from Insight Partners, Team8, and M12, Microsoft's Venture Fund. The financing follows a period of rapid commercial growth, with the company reporting more than 500% growth since the third quarter of 2025 and increasing adoption among Fortune 500 enterprises. ## [Your company can publish on HackerNoon!](https://business.hackernoon.com/business-blogging?utm_source=HackerNoon&utm_medium=targeted&utm_campaign=ads) [](https://hackernoon.com/ai-agent-logs-can-become-a-security-risk) ## [AI Agent Logs Can Become a Security Risk](https://hackernoon.com/ai-agent-logs-can-become-a-security-risk)  [byAlvin Lee@alvinslee](https://hackernoon.com/u/alvinslee) [#AI](https://hackernoon.com/tagged/ai) [](https://hackernoon.com/ai-agent-could-be-running-your-security-operations-center-to-prevent-attacks) ## [AI Agents Could Be Running Your Security Operations Center (SOC) To Prevent Attacks](https://hackernoon.com/ai-agent-could-be-running-your-security-operations-center-to-prevent-attacks) [**, a Palo Alto-based AI-native startup, has raised **$9 million in a Pre-Series A funding round** co-led by **True Global Ventures (TGV)** and **Accel**, with participation from **[Kickstart Ventures](https://kickstart.ph/)**. The latest investment brings the company’s total funding to **$14 million** and underscores a growing shift in enterprise AI investment, where investors are increasingly looking beyond applications and toward the data infrastructure that enables AI to operate effectively. The new capital will support the expansion of Sprouts.ai’s AI agent capabilities, deepen integrations with enterprise platforms, and accelerate growth of its proprietary GTM intelligence platform designed to help organizations identify, engage, and convert ideal customers through unified customer intelligence and autonomous AI workflows. “The B2B revenue stack is broken. ### **Enterprise AI Is Becoming an Infrastructure Story** ##### **Quick Takeaways** - **The funding reflects a broader shift in enterprise AI investment.** As autonomous AI agents become more prevalent, investors increasingly see reliable, integrated data infrastructure as a strategic differentiator rather than just a supporting technology.
# **How Many AI Agents Are Too Many?** NTT Research and Harvard University **Research Reveals Key Insights for Using Agentic AI in the Workplace** Hidenori Tanaka and Elizabeth Pavlova from [NTT Research's Physics of Artificial Intelligence (PAI) Lab](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fntt-research.com%2Fpai-group%2F&esheet=54578266&newsitemid=20260728154606&lan=en-US&anchor=NTT+Research%27s+Physics+of+Artificial+Intelligence+%28PAI%29+Lab&index=1&md5=488798bff552b49015e51ead04cd0620), in collaboration with [Harvard University's Center for Brain Science](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fcbs.fas.harvard.edu%2F&esheet=54578266&newsitemid=20260728154606&lan=en-US&anchor=Harvard+University%27s+Center+for+Brain+Science&index=2&md5=e721ac98b941e262f3f353ad36a18349), challenges the assumption that simply adding more AI agents automatically improves enterprise AI performance. The research paper titled, “ [**Flag Game: Interpreting Decision Mechanisms of Bounded Social Agents”**](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fopenreview.net%2Fforum%3Fid%3D4uxDZTYd7U&esheet=54578266&newsitemid=20260728154606&lan=en-US&anchor=Flag+Game%3A+Interpreting+Decision+Mechanisms+of+Bounded+Social+Agents%26%238221%3B&index=3&md5=246a887ec929f90843780fc94e375a49) [was presented at AI4Good Workshop at ICML](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fopenreview.net%2Fforum%3Fid%3D4uxDZTYd7U&esheet=54578266&newsitemid=20260728154606&lan=en-US&anchor=was+presented+at+AI4Good+Workshop+at+ICML&index=4&md5=d6d2d9f938ceff29d2b088c290a944d4). NTT Research is the Silicon Valley research arm of [NTT](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.global.ntt%2F&esheet=54578266&newsitemid=20260728154606&lan=en-US&anchor=NTT&index=5&md5=a381e5d9811616ff5d82fcc9db491c8c), one of the world's largest technology and business solutions providers. From its headquarters in Sunn
Delaware has proposed a new corporate structure, the artificial intelligence company (AIC), designed to give autonomous AI agents a recognisable legal...
The platform helps companies discover, manage and control access to their systems from non-human accounts, such as AI agents, as non-human identities will soon outnumber human users, the startup said. In May, Cyera announced a deal to [buy](https://www.timesofisrael.com/six-month-old-israeli-startup-is-bought-by-cyber-unicorn-cyera-for-about-50-million/) Israeli AI startup Genie Security after purchasing Israeli startup Ryft in April, and snapping up local startups Otterize and Shape AI in June, and Trail Security in 2024. - [AI agents](https://www.timesofisrael.com/topic/ai-agents/)
In a major move to protect enterprise networks, Hush Security raises $30M in a Series A funding round. Strategic investor Akamai Technologies joined...
A New York-based AI startup is suing Rippling – [a Silicon Valley software giant](https://nypost.com/2025/04/03/business/ex-rippling-employee-spied-on-firm-for-rival-was-asked-to-be-like-james-bond/) that got a [$3 million tax break from Gov. Kathy Hochul](https://www.governor.ny.gov/news/governor-hochul-announces-rippling-expand-new-york-city-operations-creating-more-350-new-tech) – for allegedly stealing its trade secrets to “build essentially a clone” of its safety and governance product, The Post has learned.
Hugging Face reconstructed over 17000 events after an autonomous agent reached production. Emily Hartstone's The Root closes the Runtime Authority trilogy.
Daon secures its third patent for agentic AI governance, introducing a 'digital permission slip' to authorize autonomous agent actions in real-time.
Our team at TinyAI.Tools builds bespoke AI solutions tailored to your business.