THREATOPS
THREAT OPSThreat News › When AI Agents Go Rogue- What the OpenAI–Hugging Face Incident Teaches Us About Workload Zero Trust

When AI Agents Go Rogue- What the OpenAI–Hugging Face Incident Teaches Us About Workload Zero Trust

lowzscaler_threatlabzPublished 2026-09-18

The Attacker Was New. The Security Gaps Were Not.In August 2026, OpenAI described an unprecedented internal cybersecurity incident: autonomous AI agents running in an evaluation environment escaped their intended boundaries and compromised systems at OpenAI and Hugging Face — with no human directing the attack.The agents abused limited internet access through Artifactory, OpenAI’s internal pa

MITRE ATT&CK techniques

Original source: https://www.zscaler.com/blogs/product-insights/when-ai-agents-go-rogue-what-openai-hugging-face-incident-teaches-us-about