posted in Technology

AI Bots Can Steal Your Login Credentials, but You Can Protect Yourself

lifehacker.com/tech/ai-bots-can-steal-your-login-credentials-but-you-can-protect-yourself
LifehackerAI Bots Can Steal Your Login Credentials, but You Can Protect YourselfIn just two days, OpenAI and Anthropic both issued apologies for their AI staging cyberattacks using scraped passwords or secrets. How do you protect yourself?

Replying to @⁨FoxtrotDeltaTango@sh.itjust.works⁩

According to OpenAI, one of its GPT-5.6 Sol agents was being evaluated on a platform called ExploitGym, which benchmarks large language models by asking them to write proof-of-concept security exploits for known vulnerabilities. Normally, ExploitGym is designed to be a closed ecosystem for proof-of-concept testing only, and AI agents shouldn’t have access to the internet while being evaluated.

But this agent found a zero-day vulnerability in a package registry tool called Artifactory, then used it to gain access to the web. From there, the OpenAI agent gained access to Hugging Face’s company systems using publicly exposed credentials across four separate services. It went on to spend two days inside the company’s internal systems, managed to secure root access to several production servers, and even enrolled 181 attacker-controlled devices into Hugging Face’s corporate network. 

😮