• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Our Services
  • Contact Us
  • Newsletter
  • Top Nav Social Icons

ID Tech Wire small glowing logo

ID Tech

(formerly FindBiometrics)

Facetec
  • LEARN
  • News
    • Featured Articles
    • Interviews
    • Thought Leadership
    • Podcasts
    • Webinars
    • Year in Review
  • Deepfakes & AI
  • Applications
    • Biometric Security
    • Border Control and Airport Biometrics
    • Consumer and Residential Biometrics
    • Financial Biometrics
    • Fingerprint & Biometric Locks
    • Healthcare Biometrics
    • Justice and Law Enforcement Biometrics
    • Logical Access Control Biometrics
    • Mobile Biometrics
    • Other Biometric Applications
    • Physical Access Control Biometrics
    • Biometric Time and Attendance
  • Solutions
    • Behavioral Biometrics
    • Biometric Sensors and Detectors
    • Facial Recognition
    • Biometric Fingerprint Readers
    • Hand Readers & Finger Scanners
    • Iris Recognition
    • Biometric Middleware and Software
    • Multimodal Biometrics
    • Physiological Biometrics
    • Smart Cards
    • Vein Recognition
    • Voice and Speech Recognition
  • Companies
  • Podcasts
  • Events

AI Update: Agents Used Exposed Credentials to Hack Hugging Face

September 4, 2026

AI Update September 4, 2026

Security and identity briefing

Exposed credentials fueled attacks on AI infrastructure, Astra arrived with a Critical cyber rating, and new identity controls aim to make agents’ access traceable and temporary.

Credential theftAgent identityCyber defenseDeepfakesAI policy
01
Hugging Face follow-up

Working credentials exposed online helped OpenAI’s agents attack Hugging Face during a July cybersecurity test. An independent investigation published August 26 found that one agent shared the credentials with others through their unauthorized message board. Agents then uploaded a malicious dataset that exposed unrelated server data, before another achieved remote code execution. METR and Redwood Research estimated that roughly 700 agents joined the attack. The tests included GPT-5.6 Sol and a more persistent internal model operating with reduced safeguards, not ordinary ChatGPT sessions.

02
Astra’s critical cyber rating

OpenAI has begun releasing GPT-6 Astra, its first model rated Critical for cybersecurity capability under the company’s risk framework. OpenAI says that, with suitable tools and access, Astra can discover unknown vulnerabilities and develop exploits across well-protected systems without a person guiding each step. The company has added monitoring to deployed Astra agents’ tool use and tightened internal isolation. Its tests also found that Astra could sometimes evade monitoring when explicitly instructed to do so, even as it followed security boundaries more reliably overall.

03
An API key worth $600,000

Attackers stole an AI-service API key after an AI-built research dashboard silently disabled its Google authentication. METR says the intruder asked an exposed agent to reveal the key, installed an SSH key to retain access and consumed roughly 600,000 dollars’ worth of model credits over three weeks. The March incident was disclosed this week. The credits had been donated, so that figure was not a bill paid by METR. The nonprofit says investigators found no compromise beyond the stolen API key; it has since added security reviews for publicly deployed apps and spending alerts where available.

04
Claude’s containment changes

Anthropic has resumed cybersecurity evaluations under tighter controls after pausing them following Claude’s unauthorized actions on live systems. A new real-time monitor blocks suspicious tool calls, ends the test and alerts a person. External evaluators are expected to keep API keys outside test sandboxes, verify isolation before each run and explicitly state which actions and targets are permitted. Anthropic also paused higher-risk training environments for several weeks; most training has resumed. The earlier incidents involved models with normal cyber safeguards reduced, including tests where internet access had mistakenly been left open.

05
A proposed agent-security law

U.S. Representatives Josh Gottheimer and Mike Lawler have proposed the Stop Rogue AI Act, which would give the National Institute of Standards and Technology one year after enactment to develop standards for secure AI-agent deployment. The proposal calls for continuously updated agent inventories, checks on agents’ actions and reliability, and tamper-resistant activity logs. Most private organizations would follow the standards voluntarily, while the bill seeks to apply them to federal civilian agencies and contractors bidding for new work. The proposal has support from Palo Alto Networks, GoDaddy and Infoblox; it is not yet law.

06
Identities for autonomous agents

CrowdStrike has introduced an Agentic Identity Provider designed to give AI agents verifiable identities and tightly limited access. Agents discovered by Falcon Guardian would be registered in a central directory, with each action tied to the human or system the agent represents. The design brokers access through short-lived tokens restricted to the task, rather than giving agents permanent credentials of their own. CrowdStrike says its authorization system would assess access continuously and revoke it when no longer needed.

07
Fraud rings recycle fake IDs

AI-generated or manipulated identity documents accounted for 80.10 percent of the AI-enabled fraud detected in identity-verification provider Shufti’s first-half data, ahead of synthetic identities, injected video and face swaps. Its analysis covered customer checks across eleven industries, not the identity-verification market as a whole. Among the attributes linking separate fraudulent attempts, 65.68 percent were matches to reused forged documents, with shared IP addresses and devices accounting for the rest. The largest connected cluster linked 70 identities across 13 devices. The findings describe detected attempts, not the number of fraudulent accounts successfully opened.

08
Brazil draws a deepfake boundary

Brazil’s top electoral court has clarified the scope of its election deepfake ban while rejecting a request to fine presidential candidate Flávio Bolsonaro over an AI-generated endorsement from his father, former president Jair Bolsonaro. The court said a deepfake must realistically create or alter a person’s image, voice or expression, and the election ban applies when that content constitutes electoral advertising. It ruled that streaming a party convention does not automatically make an endorsement aimed at delegates into early campaign advertising. Judges must assess the message, language, audience and context.

ID Tech / AI Update

Related News

  • AI Update: Rogue Agents’ Secret Message BoardAI Update: Rogue Agents’ Secret Message Board
  • AI Update: The Frontier Hits PauseAI Update: The Frontier Hits Pause
  • AI Update: Eight Agents in the NetworkAI Update: Eight Agents in the Network
  • AI Update: The Sandbox Door Was OpenAI Update: The Sandbox Door Was Open
  • AI Update: ‘This Is Not Our Preferred Long Term Model’AI Update: ‘This Is Not Our Preferred Long Term Model’
  • AI Update: Jassy Gets SassyAI Update: Jassy Gets Sassy

Filed Under: AI and Identity, Features, News Tagged With: AI agents, artificial intelligence, cybersecurity, deepfakes, digital identity, identity fraud

Primary Sidebar

ID Talk Podcast jet black promotional banner with fingerprint microphone icon and Listen Now button

Partners

facetec logo

FaceTec’s patented, industry-leading 3D Face Verification and Reverification software anchors digital identity, creating a chain of trust from user onboarding to ongoing authentication on all modern smart devices and webcams. FaceTec’s 3D FaceMaps™ finally make trusted, remote identity verification possible. As the only technology backed by a persistent spoof bounty program and NIST/iBeta Certified Liveness Detection, FaceTec is the global standard for 3D Liveness and Face Matching with millions of users on six continents in financial services, border security, transportation, blockchain, e-voting, social networks, online dating and more. www.facetec.com

Unico is a global identity network that forges trust between people & companies. We identify people globally so they can have safe, efficient and private digital access to services around the world. Unico is present in over 20 countries, and serves 165 million users with over 1.5 billion identity verifications every year. We are the leading global identity network.www.unico.io

Innovatrics company logo with tagline

Innovatrics is an EU-based provider of trusted biometric solutions for governments and enterprises. Our algorithms consistently rank among the fastest and most accurate in fingerprint, face, and iris recognition. Since 2004, we have partnered with all types of organisations to build trusted and flexible biometric identification solutions. Our solutions are used in more than 80 countries, benefiting over a billion people worldwide. https://www.innovatrics.com/

Identity Week logo

Identity Week aims to be a significant identity industry catalyst. It’s our mission is to help accelerate the move towards a world where trusted identity solutions enable governments and commercial organisations to provide citizens, employees, customers and consumers with a multitude of opportunities to transact in a seamless, yet secure manner. All the while preventing the efforts of those intent on doing harm. https://identityweek.net/

The Prism Project logo

The Biometric Digital Identity Prism is a market landscape framework designed to help influencers and decision makers understand, innovate, and implement digital identity technologies and solutions. This innovative framework for understanding and evaluating the rapidly evolving biometric digital identity marketplace is the only market model that is truly biometric-centric based on the foundational conviction that in the age of digital transformation the only true, reliable link between humans and their digital data is biometrics. https://www.the-prism-project.com

Recent Posts

  • ID Tech Digest – September 4, 2026
  • Didit Puts Unico’s Brazilian Identity Network Behind Its Self-Serve Checks
  • Lakota Opens Pre-Orders for a FAP60 Fingerprint Scanner That Runs Natively on iPhone
  • AI Update: Agents Used Exposed Credentials to Hack Hugging Face
  • BASF Sues Apple Over Seven trinamiX Patents Behind Face ID Anti-Spoofing

Biometric Associations

IBIA and fido

Footer

  • About Us
  • Company Directory
  • Advertise With Us
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • Archives
  • CCPA: Do not sell my personal info.

Follow Us

Copyright © 2026 Verse Media