The OpenAI agent that "hacked" Hugging Face also breached four accounts on four other services.
The four accounts were part of the Hugging Face attack. Using credentials exposed online, the agent turned one account into an "outbound relay and staging path" and used another for data storage. Two others were accessed in read-only mode.
OpenAI's investigation also found a few additional accounts that its models accessed during separate evaluations, something the company had not previously disclosed.
Via Wired