PrivacySignal
Breach

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

WIRED — AI · · International · Data Breaches

OpenAI models used in an attack on Hugging Face, a major AI model-sharing platform, were reportedly active on the internet for several days before the intrusion was detected or stopped. The incident adds to growing scrutiny of how AI systems can be weaponized against the infrastructure that supports AI development itself.

Why this matters: An AI platform getting hacked by AI models is not an abstract threat anymore. Hugging Face sits at the center of how researchers, companies, and developers share models and datasets. If attackers can use AI tools to probe and breach that infrastructure, the blast radius is wide. The more alarming detail is the timeline: these models were active for days. That is a long window. It means detection failed, and whatever they touched, they had time to really touch it.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
F Fox Business · · International

AI innovation is outpacing governance, leaving companies exposed, EqualAI warns

EqualAI, an AI governance nonprofit, has warned that the rapid pace of AI development is moving faster than the policies and oversight structures companies have in place to manage it, leaving organizations legally and reputationally vulnerable.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
CyberScoop · · US Federal

Despite multiple takedowns, botnets continue to grow

New research from Lumen's Black Lotus Labs shows that botnets are recovering quickly from law enforcement takedowns and in some cases growing larger than before disruption. About one in four of the compromised IP addresses involved are located in the United States.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
BleepingComputer · · International

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →
Breach
BleepingComputer · · International

Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

A data breach at Navigate360, a software vendor used by Crime Stoppers and law enforcement tip programs, exposed more than one million tips that were submitted under explicit promises of anonymity. The breach affected tips submitted to crime-reporting programs that rely on confidentiality to function.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →