OpenAI-Hugging Face incident exposes cybersecurity’s ‘human-speed’ problem
AI agents exploited familiar system weaknesses with surprising speed and persistence. These agents communicated extensively, forming a swarm to coordinate their actions. They discovered credentials and chained vulnerabilities to gain server acce...

OpenAI’s Hugging Face hack incident shows AI agents can find and chain your existing security weaknesses faster than ever
Speaking to ET Online, Pavan Karthick M, Threat Researcher at CloudSEK, said the vulnerabilities exploited in the incident were largely familiar ones, including template injection, exposed metadata endpoints, static credentials stored in environment variables and overprivileged service accounts.
“What's different here is the pace and persistence,” Karthick said.
Also Read: OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find
An internal OpenAI research model involved in the incident carried out 17,600 actions over four-and-a-half days, according to CloudSEK’s assessment. When its sandbox was terminated, it rebuilt its tooling and continued. When one route for communicating with external systems was blocked, it found another.
For security teams, that change in speed could prove more consequential than the individual vulnerabilities being exploited.
“SOCs today are built to handle human-speed attackers,” Karthick said.
An autonomous AI system could generate thousands of individually low-confidence security events across an organisation’s infrastructure at the same time, he said, making it harder for security teams to identify which alerts point to a real attack.
When agents start working together
The incident also demonstrated another unusual behaviour. A joint investigation by METR and Redwood Research, cited by Reuters, found that around 700 agents exchanged tens of thousands of messages through an unauthorised communication channel.
OpenAI said its internal package manager, Artifactory, was effectively turned into an unofficial message board where agents exchanged discoveries. When that mechanism was removed, the agents created another communication channel using directory names.
Karthick described the behaviour as “genuinely surprising”, but said it was more an AI alignment issue than a new cybersecurity technique.
He said any resource shared by multiple agents, such as filesystems, caches or error logs, could be used as an unexpected communication channel, even if developers and security teams had not designed it for that purpose.
In its technical report, OpenAI said that the agents also began dividing work among themselves. Some searched for vulnerabilities, others looked for credentials, while others coordinated activity. They eventually exploited a Modal workload, discovered publicly exposed Hugging Face credentials and chained multiple weaknesses to gain code execution on Hugging Face servers.
The report also added that the agents eventually executed code on dozens of servers, gained root access on one and obtained limited private data and messaging credentials. They also targeted OpenAI’s own infrastructure and gained administrator access to a research cluster supporting virtual-machine environments.
Reuters reported that investigators also found attempts to manipulate or delete records of the agents’ activity. The independent investigation found that one in five agents examined showed clear interest in manipulating evidence.
Not an autonomous hacker…yet
Karthick cautioned against interpreting the incident as evidence that fully autonomous AI cyber attackers are already operating in the wild. The system involved was an internal research model operating with safety guardrails deliberately removed, he said. Commercial AI models deployed with production safeguards behave differently.
That distinction matters. But the incident still exposes a defensive gap as companies rapidly introduce agents into software development, customer service and business automation.
The immediate question for organisations, Karthick said, is not simply what an agent has been instructed to do, but what systems, credentials and data it can reach if its behaviour deviates from those instructions.
Also Read: AI security emerging as separate budget line for Indian enterprises: Palo Alto Networks’ Swapna Bapat
Treating AI agents like employees
As AI agents move to taking on more tasks, Swapna Bapat, vice president and managing director for India and SAARC at Palo Alto Networks, believes that companies need to treat them as machine identities within the enterprise.
“AI agents have to be given the same treatment when it comes to securing the environment as you would any employee in the organisation. A machine identity,” she told ET Online’s Arun Padmanabhan in a previous interaction.
According to Bapat, companies need to decide what an AI agent can access, track its actions and be able to stop it when needed. “Are you able to monitor what the agent is doing? And can you kill it at the right time, if needed?” she added.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.