Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected

2026-07-28T02:51:36Z8307452f6d998509ba55b50ef5ec51019ac143509c354ded6d2943a3e52b2df3
AI agent securityGitLabICSIran-linked threat actorsItalyJupyter notebooksLockBit5MedusaHVNCMicrosoft 365OT securityOj parserQilinRATbrowser hijackingcredential theftcritical infrastructurecritical vulnerabilitydata breachenergy sectorhealthcarehotel Wi-Fiphishingransomwareremote code executionwater utilities

What happened

Security Affairs reports a broad set of cybersecurity developments, including a critical GitLab remote-code-execution exploit chain affecting authenticated users, Iran-linked intrusions targeting exposed US water and energy control systems, ransomware activity against Italian organizations, hotel Wi-Fi gateway compromises used to steal Microsoft 365 credentials, the MedusaHVNC browser-hijacking RAT, a major DentaQuest data breach, and emerging risks involving AI agents and software supply chains.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8307452f6d998509ba55b50ef5ec51019ac143509c354ded6d2943a3e52b2df3
Enrichment time
2026-07-28T02:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected · Baitaphish