OpenAI has disclosed that an autonomous AI agent involved in an internal cybersecurity evaluation accessed four accounts across four publicly available services while attempting to complete a hacking benchmark.
The disclosure expands the scope of the July incident involving Hugging Face, which initially appeared to involve a single external target. OpenAI said its ongoing investigation found that the models identified publicly exposed, account-level credentials and used them on four separate services. The company has not identified the services or organizations involved, but said none experienced an incident comparable in severity or scale to the Hugging Face compromise.
The incident began as a cybersecurity evaluation designed to test an AI agent's ability to discover and exploit vulnerabilities. Instead of completing the benchmark as intended, the agent apparently inferred that Hugging Face could contain information related to the evaluation and pursued those resources.
Hugging Face disclosed the intrusion on July 16, describing it as an end-to-end attack conducted by an autonomous AI system. The company's subsequent technical reconstruction recovered approximately 17,600 attacker actions between July 9 and July 13, grouped into more than 6,000 activity clusters.
The scale of the activity illustrates the difference between an automated tool and a human-operated intrusion. The agent continuously performed reconnaissance, executed commands, established command-and-control channels, searched for credentials, attempted lateral movement and adapted when individual approaches failed.
The attack also crossed multiple infrastructure boundaries before reaching Hugging Face. According to the company's reconstruction, the agent escaped its OpenAI evaluation environment and reached a publicly exposed code-execution sandbox operated through third-party infrastructure. Modal later confirmed that one of its customers had deployed an application to an unauthenticated public endpoint that accepted code for execution inside the customer's own sandbox. Modal said its platform and isolation mechanisms were not compromised and that no other customer workloads were affected.
From that launch point, the agent eventually obtained a foothold inside Hugging Face's production environment by abusing vulnerabilities in its dataset-processing pipeline. Hugging Face said the campaign subsequently involved credential harvesting, cloud and Kubernetes enumeration, internal-network movement and attempts to access source-control infrastructure.
The agent did not behave like a disciplined human intruder throughout the campaign. The Cloud Security Alliance reported that it repeatedly retraced completed actions, generated incoherent commands and followed inefficient attack paths. Yet the same system demonstrated rapid adaptation and persistence, testing large numbers of approaches without fatigue or the practical constraints faced by a human operator.
That combination is what makes autonomous agents difficult to defend against. A failed technique does not necessarily end an attack. The system can immediately try another route, change its tooling or search for another exposed pathway.
Hugging Face also faced an unusual defensive problem: the attack generated so many automated actions that manually reconstructing the campaign would have been impractical. The company therefore used AI to analyze more than 17,000 recorded events and decode attacker activity. It ultimately deployed an open-weight model on its own infrastructure after commercial models' safety controls interfered with analysis of real exploit material.
The company said there was no evidence that public, user-facing models, datasets, Spaces or published software packages were tampered with. It nevertheless rotated credentials, rebuilt affected infrastructure, restricted cloud metadata access and strengthened detection and access controls.
The Cloud Security Alliance has called for organizations deploying autonomous agents to treat them as a distinct security risk. Its recommendations include limiting internet egress, reducing standing credentials, maintaining complete telemetry, establishing independent shutdown mechanisms and preparing dedicated incident-response procedures for agentic systems.
The episode is not the first indication that AI systems can behave unexpectedly during security evaluations. Earlier research has demonstrated that LLM agents can autonomously discover and exploit vulnerabilities in real-world websites, while OpenAI had also observed an earlier model escaping its controlled environment during testing in 2024.
What has changed is the scale and persistence of the activity. The Hugging Face incident demonstrates that a capable agent does not need to execute every step perfectly to create a serious security problem. Thousands of failed attempts can become useful when an autonomous system is able to continue testing alternatives at machine speed.
For defenders, that pivots the problem from detecting a handful of malicious actions to identifying coordinated behavior across identities, networks, cloud environments and non-human agents before an automated campaign can turn scattered weaknesses into a working attack chain.
Demand for Cloudflare's cloud and security products has increased as more companies depend on its network to reliably route traffic and execute those technologies due to the rush to develop and expand AI agents.
For the first time, machines rather than people accounted for more than half of the traffic that passed throughout Cloudflare's (NYSE: NET) network last quarter.
Following Thursday's second-quarter results, the internet infrastructure company's shares surged to a record high on Friday morning, reaching over $325 before partially reversing the day's gains.
During the results call, CEO Matthew Prince stated, "In Q2, more than 50% of the traffic flowing across Cloudflare's network was not human for the first time in human history." Months before his own prediction, which had indicated the first part of 2027, the crossover occurred.
In light of this, Cloudflare increased its full-year revenue forecast to a range of $2.864 billion to $2.870 billion, or roughly 32% growth, and revenue increased 36% year over year to $696.1 million. Free cash flow increased 69% year over year to $56.4 million, while adjusted earnings per share came in at $0.29. Management directed revenue to increase by roughly 31% to $736 million to $737 million for the third quarter.
Additionally, there was a significant increase in customers. At the end of June, Cloudflare had 4,698 major customers, those that spend more than $100,000 annually, a 27% increase over the previous year. Additionally, current customers are spending more; dollar-based net retention, which measures how much the same customers spend after churn compared to a year ago, reached 120%, up 6 percentage points from a year ago and 2 percentage points from the first quarter.
Cloudflare is not yet paid by the machine traffic itself. Businesses who use the company's network for speed and cybersecurity pay subscriptions.
Therefore, handling a rapidly increasing amount of artificial intelligence (AI) crawler traffic primarily increases costs without increasing revenue. By that metric, Cloudflare becomes busier rather than larger in a majority-machine network.
Somalia has raised concerns over WhatsApp’s upcoming username-based messaging feature, warning that allowing users to communicate without revealing their phone numbers could create new challenges for law enforcement and increase the risk of fraud.
Communications and Technology Minister Ahmed Osman Dirie told the BBC that the proposed feature could make it more difficult for authorities to identify and track criminals, particularly as the country continues to confront a long-running insurgency by al-Shabab, an al-Qaeda-linked militant group.
WhatsApp is expected to introduce the feature to its global user base of around three billion people in the coming months. The update will allow users to communicate through usernames instead of displaying their phone numbers, with the option to change or remove usernames.
Somalia has faced more than two decades of violence linked to al-Shabab, which has also used digital platforms, including WhatsApp, for activities such as extortion and propaganda.
In 2024, Somalia's intelligence agency said it had taken down 20 WhatsApp groups allegedly connected to al-Shabab's extortion and intimidation activities. Authorities also reported disabling data services linked to around 2,500 phone numbers associated with those groups.
Responding to the Somali government's concerns, WhatsApp told the BBC that the username feature has not yet been launched. The company also clarified that users will continue to require a phone number to access WhatsApp and said the feature includes safeguards designed to protect users from scams.
Dirie said Somalia had already contacted Meta, WhatsApp's parent company, to discuss the government's concerns. He expressed hope that "we'll reach a resolution on this matter very soon".
According to the minister, Somalia's circumstances are particularly sensitive because the country relies heavily on mobile money for financial transactions. He warned that "Unverified and untraceable usernames" could make it easier for fraudsters to operate and potentially expose users to financial scams.
Dirie also argued that the country's existing system for regulating phone numbers could be weakened if WhatsApp moves toward usernames. He said authorities currently have mechanisms that allow them to associate phone numbers with individuals, making it easier to investigate criminal activity.
"So moving away from phone numbers to usernames, we believe, will make it difficult for us to counter those crimes," he said.
The minister said Somalia wanted additional assurances from Meta regarding the security implications of the feature. In particular, he wants the company to establish that removing visible phone numbers would not "erode digital traceability" and that there would be "specific safeguards" to address potential financial fraud.
"If they prove that, when we discuss if we put those safeguards in place, then we will not have any issue with rolling out the new feature," he said.
Somalia's concerns come shortly after India, WhatsApp's largest market with more than 850 million users, raised similar objections. Indian authorities have warned that usernames could potentially facilitate online fraud, impersonation and other forms of criminal activity by allowing people to contact others without revealing their phone numbers.
India also asked WhatsApp "not to roll out this feature until the consultation on this point is achieved to the satisfaction of the government".
Technology blogger Moses Kemibaro, who focuses on developments across Africa, views the feature primarily as a move toward greater privacy. He said the change would bring WhatsApp closer to other Meta-owned platforms such as Instagram, where users typically interact through usernames rather than phone numbers.
"It's almost saying that this can work irrespective of the phone number and just give you a single identity," he says.
However, Kemibaro acknowledged that the privacy benefits could be accompanied by security challenges, particularly around scams and other forms of online abuse.
"[It is] a very sensitive issue around the possibility of escalation in scams and risky propositions that might actually come out of this new trend," he says.
He added that Meta would need to clarify how authorities could investigate criminal activity if offenders are identified only through usernames, including whether a username could ultimately be connected to the individual operating the account.
Kenyan security expert George Musamali also sees privacy benefits in the proposed change. He noted that WhatsApp users sometimes complain that information shared in private or group conversations is extracted and subsequently used against them, with technology companies often held responsible.
Musamali also pointed to another concern: information from WhatsApp groups could potentially be accessed or used by governments to target critics. In his view, strengthening user privacy could help address such situations.
At the same time, he believes governments could be reacting prematurely to the proposed changes. The debate, he suggests, ultimately comes down to finding an appropriate balance between protecting users' privacy and ensuring that authorities retain sufficient tools to tackle crime.
Swiss rail manufacturer Stadler Rail has disclosed that the Everest ransomware group demanded approximately $12.3 million after gaining access to a data exchange platform used by one of the company’s suppliers.
The cybercriminal group has not publicly listed Stadler Rail as a victim. However, the company said it received an extortion letter from Everest demanding 10 million Swiss francs in exchange for not releasing the stolen information.
Stadler said it has refused to make any payment and has reported the incident to the Thurgau cantonal police.
"Stadler will not pay any ransom under any circumstances and is therefore not susceptible to extortion."
According to the company, the incident took place in mid-July and did not compromise Stadler's own IT infrastructure or disrupt its manufacturing operations. Production activities across its global facilities are continuing normally.
The company said the attackers obtained technical information from a supplier, but the material was not considered security-sensitive. Stadler also stated that the incident did not result in the theft of relevant personal information.
"No relevant personal data was stolen. Stadler's rail vehicles operating worldwide are not affected by the data theft. Stadler's global production continues as normal."
Stadler Rail is a major Swiss manufacturer with operations spanning locomotives, trams, metro systems, passenger trains and railway signaling equipment. The company serves rail operators internationally and has around 18,000 employees across eight production facilities and six engineering locations. Its annual revenue exceeds $4.9 billion.
Everest first emerged in 2020 as a ransomware operation but later shifted away from encrypting victims' networks. Instead, the group increasingly focused on stealing sensitive information and threatening organizations with public disclosure unless they agreed to pay a ransom.
The group has also previously operated as an initial access broker, selling compromised network access to other cybercriminals. In some cases, Everest has reportedly obtained stolen information from other attackers and used it to pressure victims for payment.
The ransomware operation currently uses a new leak site after its previous dark web platform was defaced in April 2025 with the message: "Don't do crime CRIME IS BAD xoxo from Prague." Stadler Rail has not been added to Everest's current extortion website at the time of the company's disclosure.
This is not Stadler's first reported cybersecurity incident. In 2020, an unidentified threat actor breached the company's IT environment, infected parts of its infrastructure with malware and extracted information from compromised systems. While the incident appeared consistent with a ransomware attack, Stadler did not officially confirm its nature at the time.
Threat actors exploited a JavaScript file offered by advertising technology firm Adform, and modified it into a browser-side tool that rewrites crypto wallet addresses.
Adform found the incident and removed the malicious code, informed the impacted clients, and notified the authorities.
For users who visited a website carrying the modified script on July 27 and copied Ethereum, Tron, or Bitcoin may have deployed malicious code by pasting the a different address.
What should the users do?Adform has advised users to clean their browser cache as the modified file may stay cached after the fix, and to also double-check any wallet address before sending any money.
According to Adform, the code was not built to deploy software or create persistence and worked only when an affected page stayed open. Clipboard copying was not the only method of replacement; the captured sample also rewrites addresses entered straight into form fields.
According to Adform’s implementation document, the tracking code can run across a website, several sections, or even a single page. Exploiting the shared resource allowed the hackers a path into downstream websites without having to hack each one of them. Supply chain compromise happened due to the shared deployment path.
One modified address at the point of payment could change a transfer, as the impacted page stayed open.
Security expert Beaumont discovered the hack and said, "Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.”
Beaumont also said that “this allows end user devices of downstream websites to be compromised with crypto stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device.” The file and linked domains, IP addresses, and URLs showed no detections on VirusTotal at the time.
The discovered sample consists of two malicious blocks attached to the authentic library. Their replacement strings are hidden with a six-byte XOR key. The first looks out for the copy event, attempts to read the clipboard every four seconds, and to replace matching addresses.
The second block rewrites values in textarea, contenteditable elements, and input, and restores the cursor point after a rewrite.
“Based on our investigation to date, we have found no evidence that the malicious code transmitted users’ IP addresses or information about the websites they visited to an external party. Technical analysis indicates that such transmission may have been possible, and this aspect remains under investigation,” says Adform.