{"id":20727,"date":"2026-07-29T07:57:49","date_gmt":"2026-07-29T02:57:49","guid":{"rendered":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=20727"},"modified":"2026-07-29T07:57:49","modified_gmt":"2026-07-29T02:57:49","slug":"scoop-second-account-accessed-by-openais-agent-tied-to-cyber-safety-testing","status":"publish","type":"post","link":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=20727","title":{"rendered":"Scoop: Second account accessed by OpenAI&#039;s agent tied to cyber safety testing"},"content":{"rendered":"<p><script>\r\n  atOptions = {\r\n    'key' : '644b717812d811d6a1c1fc5b6ccd6fa6',\r\n    'format' : 'iframe',\r\n    'height' : 90,\r\n    'width' : 728,\r\n    'params' : {}\r\n  };\r\n<\/script>\r\n<script src=\"https:\/\/www.highperformanceformat.com\/644b717812d811d6a1c1fc5b6ccd6fa6\/invoke.js\"><\/script>\r\n<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.axios.com\/ilQHvNf-pEeFHD-VkOy24TwmlO4=\/1366x768\/smart\/2023\/04\/09\/203409-1681072449747.jpg\" \/><\/p>\n<p>The OpenAI agent that accessed <a href=\"https:\/\/www.axios.com\/2026\/07\/28\/openai-hugging-face-modal-labs-hack\" target=\"_blank\">a third-party system<\/a> during the Hugging Face incident reached infrastructure tied to CyberGym, the project behind the ExploitGym benchmark it had been assigned to solve, a source familiar with the matter told Axios.<\/p>\n<p><strong>Why it matters: <\/strong>The new details suggest the OpenAI agent continued pursuing its assigned objective even after escaping its testing environment, rather than abandoning the task it had been given.<\/p>\n<hr>\n<p><strong>Catch up quick<\/strong>: OpenAI&#8217;s AI agent system <a href=\"https:\/\/www.axios.com\/2026\/07\/28\/openai-hugging-face-modal-labs-hack\" target=\"_blank\">accessed an asset<\/a> belonging to a customer of Modal Labs as part of <a href=\"https:\/\/www.axios.com\/2026\/07\/21\/openai-says-hugging-face-breach-caused-by-one-its-models\" target=\"_blank\">the Hugging Face incident<\/a> earlier this month, Modal&#8217;s top tech executive confirmed on Tuesday. <\/p>\n<ul>\n<li>In an update <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\">published<\/a> Tuesday, OpenAI said the models escaped the sandbox and gained internet access after exploiting a previously unknown vulnerability in Artifactory, software commonly used to cache package repositories.<\/li>\n<li>Hugging Face <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" target=\"_blank\">said<\/a> the models then abused a &#8220;public code-evaluation external sandbox hosted on a third-party provider&#8217;s infrastructure&#8221; and used that sandbox as a launchpad for the agent. <\/li>\n<li>Modal CTO Akshat Bubna told Axios in a statement that &#8220;Modal&#8217;s platform was not compromised in any way&#8221; during the incident. <\/li>\n<li>The customer had left an endpoint exposed that allowed anyone on the internet to execute code inside its sandboxes, he added.  <\/li>\n<\/ul>\n<p><strong>Between the lines: <\/strong>The incident underscores how aggressively frontier AI agents may pursue the objectives they&#8217;re assigned \u2014 even if doing so means finding unintended ways to access information needed to complete an evaluation.<\/p>\n<ul>\n<li>During the incident, OpenAI&#8217;s models were trying to solve ExploitGym, which asks models to write proof-of-concept exploits for known security vulnerabilities.<\/li>\n<li>Hugging Face noted in its technical report that the only customer assets accessed in its breach were &#8220;the set of ExploitGym\/CyberGym challenge solutions stored in five datasets.&#8221;<\/li>\n<li>A source familiar with the matter told Axios the agent accessed the CyberGym-associated Modal customer asset while attempting to complete that same evaluation.<\/li>\n<li>Modal declined to comment on the CyberGym connection.<\/li>\n<\/ul>\n<p><strong>The big picture<\/strong>: Researchers have found that frontier AI models are <a href=\"https:\/\/www.axios.com\/2026\/07\/23\/openai-hugging-face-cyber-hacks-testing\" target=\"_blank\">increasingly<\/a> looking for ways to <a href=\"https:\/\/www.aisi.gov.uk\/blog\/cheating-behaviour-in-frontier-model-evaluations\" target=\"_blank\">cheat<\/a> during model evaluations and that they appear to recognize when they&#8217;re being evaluated.<\/p>\n<ul>\n<li>The U.K.&#8217;s AI Security Institute <a href=\"https:\/\/www.aisi.gov.uk\/blog\/cheating-behaviour-in-frontier-model-evaluations\" target=\"_blank\">said<\/a> last week that every model it tested attempted to cheat at least some of the time on its cybersecurity evaluations.<\/li>\n<\/ul>\n<p><strong>What to watch<\/strong>: The debate over how to evaluate and control advanced AI systems is also intensifying. <\/p>\n<ul>\n<li>More than 1,100 employees at AI companies released a letter Tuesday calling on the U.S. government to establish ways to halt development of AI models. <\/li>\n<\/ul>\n<p><strong>Go deeper<\/strong>: <a href=\"https:\/\/www.axios.com\/2026\/07\/24\/ai-safety-security-testing-hugging-face\" target=\"_blank\">The people testing AI for danger can&#8217;t keep up<\/a><\/p>\n<script async=\"async\" data-cfasync=\"false\" src=\"https:\/\/pl30214220.effectivecpmnetwork.com\/9ab3d4df8a7e1a6171e16ddbf732cc19\/invoke.js\"><\/script>\r\n<div id=\"container-9ab3d4df8a7e1a6171e16ddbf732cc19\"><\/div>\r\n\n","protected":false},"excerpt":{"rendered":"<p>The OpenAI agent that accessed a third-party system during the Hugging Face incident reached infrastructure tied to CyberGym, the project behind the ExploitGym benchmark it had been assigned to solve, a source familiar with the matter told Axios. Why it matters: The new details suggest the OpenAI agent continued pursuing its assigned objective even after&#8230;<\/p>\n","protected":false},"author":1,"featured_media":20728,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.axios.com\/ilQHvNf-pEeFHD-VkOy24TwmlO4=\/1366x768\/smart\/2023\/04\/09\/203409-1681072449747.jpg","fifu_image_alt":"","footnotes":""},"categories":[17],"tags":[],"class_list":["post-20727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-political-news"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/20727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20727"}],"version-history":[{"count":0,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/20727\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/media\/20728"}],"wp:attachment":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}