Security Advisory: AI Agents as Cyber Operators
An Artificial Intelligence (AI) agent broke into a company's network, moved through its systems for four days, and carried out more than 17,000 recorded actions, all without a human at the keyboard.
This was not a hypothetical or a red-team exercise gone public. It happened this month at Hugging Face, one of the most widely used platforms for hosting AI models, and the agent responsible was built by OpenAI as part of an internal cybersecurity evaluation.
ISI Cyber is issuing this cyber advisory because the incident offers a concrete, documented example of the risks organizations face as AI agents grow more capable of autonomous, multi-step action.
Dig deeper and continue reading below.
WHAT HAPPENED
Hugging Face recently disclosed that an autonomous AI agent gained unauthorized access to part of its environment.
OpenAI later confirmed that the activity occurred during an internal cybersecurity evaluation. According to public reporting, the models identified a vulnerability, gained internet access, and accessed Hugging Face systems while attempting to complete the evaluation.
And now, OpenAI has confirmed that the same agent also accessed a customer environment at a second company, Modal Labs, through an exposed endpoint, and that OpenAI did not detect the activity until after Hugging Face had already contained it and notified the FBI.
- OpenAI attributed the activity to a combination of models, including GPT-5.6 Sol and an unreleased, more capable model, run with reduced safety restrictions for the evaluation
- Hugging Face rotated all credentials, dismantled the compromised systems, and rebuilt roughly a third of its infrastructure from clean images
- Customer-facing models, datasets, and Spaces on Hugging Face were not affected; impact was limited to internal evaluation datasets and one downstream customer environment
WHY THIS MATTERS
This does not mean everyday chatbots are independently attacking companies.
However, it does show that advanced AI agents are becoming capable of carrying out complex, multi-step cyber activity with limited human direction.
Depending on how they are configured, these systems may be able to:
- Execute code
- Use connected tools
- Identify vulnerabilities
- Access credentials
- Perform thousands of actions at machine speed
WHAT YOU SHOULD TAKE FROM THIS
AI agents should be treated like privileged automation, not ordinary productivity tools.
Before adopting an AI agent, organizations should clearly define:
- The business owner of the AI Agent
- The business purpose for using it
- What data, systems, and applications it may access
- Detailed logging and monitoring
- Which users may operate it
- What actions it is allowed to take
- When human approval is required
- How the agent can be disabled or contained
Contractors should complete their own internal review and risk assessment before connecting an AI agent to production systems, identities, sensitive data, or business applications.
The same logging, evidence, and ownership discipline contractors are already building for CMMC applies directly here. See our guidance on whether you need a GRC platform for CMMC and on why CMMC is a business risk issue, not just a cyber one.
WHAT THE ISI CYBER TEAM IS WATCHING
ISI Cyber will continue monitoring:
- AI-assisted cyberattacks
- Agents bypassing intended controls
- Prompt injection and connected-tool abuse
- Unauthorized access to credentials and production systems
- New guidance for securely deploying agentic AI
No immediate action is required based on this event. We are sharing this advisory because it provides an early look at how cyberattacks and cyber defense may change as AI agents become more capable.
Stay safe, stay secure.
-ISI Cybersecurity Team
REFERENCES
- OpenAI: Security incident during model evaluation
- Hugging Face: Security incident disclosure
- UK NCSC: Thinking carefully before adopting agentic AI
- BBC article: Firm hacked by rogue OpenAI models says it is 'a wake-up call'
- Axios: OpenAI says Hugging Face breach caused by one of its models
- BleepingComputer: OpenAI agent used exposed credentials at 4 services in Hugging Face breach


