Skip to content

Security Advisory: AI Agents as Cyber Operators

Listen: Security Advisory: AI Agents as Cyber Operators
3:52

An Artificial Intelligence (AI) agent broke into a company's network, moved through its systems for four days, and carried out more than 17,000 recorded actions, all without a human at the keyboard.

This was not a hypothetical or a red-team exercise gone public. It happened this month at Hugging Face, one of the most widely used platforms for hosting AI models, and the agent responsible was built by OpenAI as part of an internal cybersecurity evaluation.

ISI Cyber is issuing this cyber advisory because the incident offers a concrete, documented example of the risks organizations face as AI agents grow more capable of autonomous, multi-step action.

Dig deeper and continue reading below.


WHAT HAPPENED 

Hugging Face recently disclosed that an autonomous AI agent gained unauthorized access to part of its environment. 

OpenAI later confirmed that the activity occurred during an internal cybersecurity evaluation. According to public reporting, the models identified a vulnerability, gained internet access, and accessed Hugging Face systems while attempting to complete the evaluation. 

And now, OpenAI has confirmed that the same agent also accessed a customer environment at a second company, Modal Labs, through an exposed endpoint, and that OpenAI did not detect the activity until after Hugging Face had already contained it and notified the FBI.

  1. OpenAI attributed the activity to a combination of models, including GPT-5.6 Sol and an unreleased, more capable model, run with reduced safety restrictions for the evaluation
  2. Hugging Face rotated all credentials, dismantled the compromised systems, and rebuilt roughly a third of its infrastructure from clean images
  3. Customer-facing models, datasets, and Spaces on Hugging Face were not affected; impact was limited to internal evaluation datasets and one downstream customer environment

WHY THIS MATTERS 

This does not mean everyday chatbots are independently attacking companies. 

However, it does show that advanced AI agents are becoming capable of carrying out complex, multi-step cyber activity with limited human direction.

Depending on how they are configured, these systems may be able to:

  • Execute code
  • Use connected tools
  • Identify vulnerabilities
  • Access credentials
  • Perform thousands of actions at machine speed

WHAT YOU SHOULD TAKE FROM THIS 

AI agents should be treated like privileged automation, not ordinary productivity tools. 

Before adopting an AI agent, organizations should clearly define: 

  • The business owner of the AI Agent
  • The business purpose for using it 
  • What data, systems, and applications it may access 
  • Detailed logging and monitoring 
  • Which users may operate it  
  • What actions it is allowed to take  
  • When human approval is required 
  • How the agent can be disabled or contained 

Contractors should complete their own internal review and risk assessment before connecting an AI agent to production systems, identities, sensitive data, or business applications. 

The same logging, evidence, and ownership discipline contractors are already building for CMMC applies directly here. See our guidance on whether you need a GRC platform for CMMC and on why CMMC is a business risk issue, not just a cyber one.

WHAT THE ISI CYBER TEAM IS WATCHING 

ISI Cyber will continue monitoring: 

  • AI-assisted cyberattacks 
  • Agents bypassing intended controls 
  • Prompt injection and connected-tool abuse 
  • Unauthorized access to credentials and production systems 
  • New guidance for securely deploying agentic AI 

No immediate action is required based on this event. We are sharing this advisory because it provides an early look at how cyberattacks and cyber defense may change as AI agents become more capable. 

Stay safe, stay secure.

-ISI Cybersecurity Team


REFERENCES 

Related Posts