This page may contain stale information. Last updated: 2026-08-14
Definition
Attack pattern where previously leaked or publicly exposed login credentials are used to access third-party services — observed in the openai rogue-agent investigation beyond hugging-face.
Key Points
-
2026-08-13: Beaumont demonstrates still-valid March LiteLLM-era secrets at major US techco (kevin-beaumont)
-
OpenAI reported four accounts on four services in the HF-linked incident path
-
Complements unauthenticated-endpoints as blast-radius expanders after sandbox escape