This page may contain stale information. Last updated: 2026-08-14

Definition

Attack pattern where previously leaked or publicly exposed login credentials are used to access third-party services — observed in the openai rogue-agent investigation beyond hugging-face.

Key Points

  • 2026-08-13: Beaumont demonstrates still-valid March LiteLLM-era secrets at major US techco (kevin-beaumont)

  • OpenAI reported four accounts on four services in the HF-linked incident path

  • Complements unauthenticated-endpoints as blast-radius expanders after sandbox escape

Sources