When 1Passwordâs chief information security officer heard about a rogue OpenAI model hacking Hugging Face, he wasnât totally surprised.
âI think this was inevitable to a certain degree [based on] the capabilities that we’re seeing, and just the rapid change of the technology,â Jacob DePriest told BetaKit. But the fact that it was completely autonomous was still shocking to see, he said.
âThis wasn’t one vulnerability or one mistake. It was a chain of different techniques working together.â
Julien Richard, Lastwall
The world is still learning the full details of the incident that led OpenAI agents to autonomously break through company guardrails and access US AI startup Hugging Faceâs internal systems, as well as other âpublicly available services.â Anthropic has since revealed that its agents also breached external organizationsâ security without being instructed to do so. Security leaders at Canadian cybersecurity firms say theyâre preparing for more AI agent threat vectors, but that the OpenAI hack was a complex operation with no catch-all solution.
OpenAI said in a blog post that the incident arose in part because certain deployment safeguards werenât enabled. Still, Julien Richard, vice-president of information security at Fredericton, NB-based Lastwall, called the agent a âpretty capable attackerâ and said that no single product could have stopped it.Â
âThis wasn’t one vulnerability or one mistake,â Richard wrote to BetaKit in an email. âIt was a chain of different techniques working together.â
DePriest agreed that the attack was sophisticated and stopping it would not have been simple.
âTo be clear, I don’t think necessarily any of our products could have stopped this,â DePriest said. He explained that the model escaped its initial containment through a complicated pattern involving a âzero-dayâ vulnerabilityâmeaning that the breached company didnât know the exposure existedâas well as data ingress, when the attacker brings data into its new environment.Â
RELATED: 1Password acquires Apono to become the âcontrol planeâ for businesses using agentic AI
âIncidents like this reinforce that identity is still one of the foundational security controls, even as attackers become more sophisticated,â Richard said, adding that it just affirms a focus on identity verification within cyber environments.
DePriest, who previously held a security leadership role at GitHub and worked for the US National Security Agency, added that 1Password stood up a security research team earlier this year. He said the company has access to advanced models for testing through OpenAIâs Trusted Access for Cyber and Anthropicâs Project Glasswing.
âThe challenges of the pastâof keeping identity safe at scaleâneed more tools, and our customers need more tools,â DePriest said.
Feature photo courtesy of Kevin Horvat via Unsplash.
