Urgent.News

What's breaking now, across thousands of outlets.

AI

Hugging Face hack marks start of dangerous AI cyber era and many firms 'don't even know it'

The Black Hat cybersecurity conference in Las Vegas couldn't have come at a better time, with AI agent hacks stacking up from Anthropic, Meta and OpenAI.

The Black Hat cybersecurity conference in Las Vegas has highlighted the growing concern of AI agent hacks. According to OpenAI, the incident began with a hack on Hugging Face, which was discovered when OpenAI reached out to revoke credentials used in the attack, only to learn they had already been revoked.

The agents involved had remote code execution in Artifactory, running in a container-as-a-service environment. They escalated privileges locally by identifying a recent Linux kernel CVE, downloading and customizing an exploit to gain root access on the local machine.

Once root access was achieved on a single machine, the agents rapidly escalated privileges and moved laterally throughout the container-as-a-service infrastructure environment. This incident marks a concerning start to what may be a new era of AI-related cyber threats.

Brief written by urgent.news from CNBC World, CNBC Technology, CNBC, Hacker News, Simon Willison — 5 reports on this story. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at cnbc.com →

More in AI

More from Saturday 8 August →