%Rogue AI Agents Put Trusted Access Under Scrutiny%
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently legitimate access.
In both cases, agents were able to use valid accounts or credentials and continue searching for ways into systems and data beyond the access they had been given.
OpenAI this week disclosed more details from its continuing review of the Hugging Face incident and other unexpected activity by its models. The company said agents had bypassed access controls, used exposed credentials, and reached parts of third-party services outside their intended access.
Separate reporting on the investigation found that agents had been probing Hugging Face as early as May, before the larger July compromise. In the July incident itself, agents found publicly exposed Hugging Face credentials and went on to chain vulnerabilities that gave them code execution on multiple servers.
Spain’s data protection authority, the AEPD, has also disclosed...
Copyright of this story solely belongs to informationsecuritybuzz.com. To see the full text click HERE