OpenAI has yet to address many questions about the AI hacking incident it disclosed a week ago that led to the "unprecedented" attack on Hugging Face, but Hugging Face shed a little more light on what happened in a blog post Tuesday.
In the post, entitled "Anatomy of a Frontier Lab Agent Intrusion," Hugging Face revealed that after it broke out of the company's own testing sandbox, OpenAI's agents "then abused a public code-evaluation external sandbox hosted on a third-party provider's infrastructure. It was able to run commands as root/admin on that external sandbox and used it as a control, staging, and egress base for the entire campaign: it acted as an external launchpad for the agent."