Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      'Really embarrassing': SA expert on OpenAI's agent escape - Dominic White

      ‘Really embarrassing’: SA expert on OpenAI’s agent escape

      28 September 2026
      Major bank joins crypto fight against Reserve Bank draft rules

      Major bank joins crypto fight against Reserve Bank draft rules

      28 September 2026
      The steam engine lesson AI doomsayers keep missing - Sam Clarke

      The steam engine lesson AI doomsayers keep missing

      28 September 2026
      Spar2U to get a do-over

      Spar2U to get a do-over

      28 September 2026
      OpenAI's rogue agent problem keeps getting bigger - Sam Altman

      OpenAI’s rogue agent problem keeps getting bigger

      28 September 2026
    • World
      Anthropic weighs new model launch to blunt OpenAI's Astra surge - Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman

      Anthropic weighs new model launch to blunt OpenAI’s Astra surge

      21 September 2026
      Hackers hack hackers: ShinyHunters seizes cl0p's dark web site

      Hackers hack hackers as dark web feud erupts

      21 September 2026
      Film piracy malware is reaching corporate machines

      Film piracy malware is reaching corporate machines

      21 September 2026
      Crypto's big bet fails as US senate sinks Clarity Act

      Crypto’s big bet fails as US senate sinks Clarity Act

      16 September 2026
      'This is not circular': Jensen Huang defends $3.5-billion MediaTek deal

      ‘This is not circular’: Jensen Huang defends $3.5-billion MediaTek deal

      2 September 2026
    • In-depth
      Meta to the AI industry: slow down without us - Mark Zuckerberg

      Meta to the AI industry: slow down without us

      16 September 2026
      Google DeepMind CEO Demis Hassabis. Image: John Sears

      The plan to stop AI from breaking the world

      16 July 2026
      The internet has a Strait of Hormuz problem

      The internet has a Strait of Hormuz problem

      15 July 2026
      AI boom sparks rally, frenzy and fear

      AI boom sparks rally, frenzy and fear

      11 June 2026
      Every plug-in hybrid on sale in South Africa, ranked by price - Lamborghini Temerario

      Every plug-in hybrid on sale in South Africa, ranked by price

      7 June 2026
    • TCS
      TCS | Octotel's Trevor van Zyl on the fibre merger question

      TCS | Octotel’s Trevor van Zyl on the MetroFibre merger question

      16 September 2026
      Meet the CIO | Shoprite's Chris Shortt on what a supermarket becomes

      Meet the CIO | Shoprite’s Chris Shortt on what a supermarket becomes

      9 September 2026
      Rubicon's EV charging network is profitable - and growing fast - Watts & Wheels

      Rubicon’s EV charging network is profitable – and growing fast

      8 September 2026
      Winstone Jordaan on building a national EV charging network

      Winstone Jordaan on building a national EV charging network

      2 September 2026
      Watts & Wheels S1E8: 'Tesla lands in Africa, just not here'

      Watts & Wheels S1E8: ‘Tesla lands in Africa, just not here’

      24 August 2026
    • Opinion
      Regulating AI: apply the laws we have first - Dirk de Vos

      Regulating AI: apply the laws we have first

      21 September 2026
      The end is nigh, and the shares go on sale in October - Duncan McLeod

      The end is nigh, and the shares go on sale in October

      14 September 2026
      The fragile joint in the Capitec machine - Pambos Soteriades

      The R197-billion market the banks can’t reach

      25 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      Management consulting as we know it is over

      21 August 2026
      South African tech's compounding debt problem - Jannie van Zyl

      The most dangerous customer is the quiet one

      10 August 2026
    • Company Hubs
      • 1Stream
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • Ascent Technology
      • AvertITD
      • BBD
      • Braintree
      • CallMiner
      • CambriLearn
      • CM.com
      • Contactable
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • HOSTAFRICA
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • Kaspersky
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Telviva
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Vox
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
      • Watts & Wheels
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » ‘Really embarrassing’: SA expert on OpenAI’s agent escape

    ‘Really embarrassing’: SA expert on OpenAI’s agent escape

    Orange Cyberdefense’s Dominic White says the Hugging Face breach was more security failure than AI marvel.
    By Fanie van Rooyen28 September 2026
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    Get breaking news on WhatsApp

    'Really embarrassing': SA expert on OpenAI's agent escape - Dominic White
    Orange Cyberdefense’s Dominic White

    The global reaction when OpenAI’s agents escaped a test environment and broke into Hugging Face’s systems in July was that the machines had become frighteningly capable. Dominic White’s reaction was that OpenAI’s security was frighteningly poor.

    His critique comes as OpenAI deals with yet another escape. On 25 September, the company disclosed that an agent in training had reached an outside chatbot on 20 September through a gap in its sandbox’s internet restrictions – the first such breakout since it hardened its test environments after the Hugging Face attack. It has again paused training and tool-using work on its most capable models.

    White, MD for South Africa at Orange Cyberdefense and a 16-year veteran of SensePost, the group’s ethical hacking arm, told TechCentral the sophistication narrative tells only half the story.

    Any hack has been the work of a ‘sophisticated’ threat actor according to PR teams for as long as it’s been going

    “When I first heard about this, it was portrayed as sophisticated. That’s not anything new in our industry. Any hack has been the work of a ‘sophisticated’ threat actor according to PR teams for as long as it’s been going. Not always been true.”

    Parts of the attack chain were genuinely sophisticated, he said. But when OpenAI presented its account at the Black Hat security conference in Las Vegas in August, “what fascinated me is that the initial attack was so mundane”.

    The agents sat in a sandbox – an isolated test environment – that could reach an internal server running Artifactory, JFrog’s package management software, which they used to fetch software packages. OpenAI later found previously unknown vulnerabilities in Artifactory, but the initial opening was simple.

    ‘Really embarrassing’

    “The initial vulnerability was that all the agents had the same shared credential and could just write files to the web server with HTTP PUT requests.” In other words, every agent used the same login and could upload files to the server at will. White called that “really embarrassing”.

    “If an organisation gave all of their customers the same password, and then customers could just write files to a web server or delete it, we go, that’s negligence.”

    The initial vulnerabilities were “quite frighteningly weak”, he said, which made him question whether OpenAI understood its duty of care.

    His second objection is that, rather than locking down after the first breach, “they let it happen again”, this time through an unauthenticated WebDAV request – a file-management command the server accepted without any login. OpenAI’s own timeline bears this out. On 8 July it rebuilt Artifactory, revoked the agents’ credentials and restarted its cybersecurity tests; the same day, agents rebuilt their covert message board using unauthenticated WebDAV requests.

    His third is that the agents ran for long periods without guardrails. “They knew they were running long-term agents here without cyber guardrails in place. So they kept it alive for a long time without [proper] monitoring. They’re just like, well, we’ve got a sandbox. Except, it was a weak sandbox.”

    Check Point's Adam Ely
    Check Point’s Adam Ely

    OpenAI has conceded much of this. In its incident report, published on 26 August, it said the chain-of-thought monitors it uses to watch its models’ reasoning were not running on these evaluations, and that an internal team had seen the agents’ message board and unauthorised internet access as early as late May – warning signs that, in hindsight, should have prompted an earlier response. The company said the incident “should never have occurred”.

    White also pointed to independent analysis showing how readily the agents crossed the line. An investigation by AI safety researchers at METR and Redwood Research found that more than 90% of the 533 agents active on the agents’ message board during the period it examined joined the attack on Hugging Face, many of them recognising it was out of scope. “If it was a swarm of humans, there would be a lot more debate about whether this is ethical, whether this is the right thing to do. But that didn’t exist here.”

    His verdict: “You’ve got poorly aligned, long-running, offensive agents running in wet paper bag sandboxes. I think the big problem here is the lab might not be doing their job.”

    You’ve got poorly aligned, long-running, offensive agents running in wet paper bag sandboxes

    OpenAI has not released the agents’ full chain-of-thought records – their step-by-step reasoning – White noted, limiting outside scrutiny. It has published excerpts, and gave the METR and Redwood researchers access to about 1 300 raw transcripts on its premises.

    Adam Ely, cybersecurity firm Check Point’s GM of AI security, who joined the interview for an upcoming episode of the TechCentral Show, was slower to pile on criticism but did not disagree. He called the incident “one of the most fascinating kind of events that I think we’ve seen in cybersecurity for a long time”.

    Individually, he said, the vulnerabilities and the agents’ tactics were well understood. What stood out was “the misalignment of the agent to the human intent” – the gap between what the agents did and what their operators wanted – and the scale at which they organised themselves.

    Ely also noted that one of the presenters at OpenAI’s Black Hat talk is “probably one of the smartest people that I’ve known throughout my entire career”.

    Every dependency is a door

    “When you look at the security teams, these are knowledgeable people. This wasn’t a fly-by-night, just kind of thrown together set of organisations.”

    Ely’s own researchers had seen similar behaviour before, in environments where the open question was whether it could happen to a serious operation. “Would a well-resourced team, a responsible company run into the same problems? Or were we only seeing this in teams that were just starting out and they hadn’t got going enough yet with their protections?” In his view, the Hugging Face incident answered that question.

    Test environments still need to pull packages and reach internal services, and every dependency is a door. “Anytime that you have to rely on an external service, maybe it’s a DNS service, maybe it’s a package manager, a vulnerability, a misconfiguration, that’s the gateway out or the gateway in.”

    OpenAI’s 20 September escape fits that description. The agent reached the outside chatbot through inadequate filtering of DNS, the system that translates web addresses into network locations.

    What was new, Ely said, was seeing long-understood weaknesses exploited at massive scale, without humans. No amount of resourcing removes the risk: “No matter what you resource and how you design, the fact is there’s some level of probability that agents are going to go rogue.”

    OpenAI
    Dado Ruvic/Reuters

    The lesson Ely draws is not that OpenAI was uniquely careless, but that ordinary discipline now carries more weight: “The basics really matter in the infrastructure and the design and the incident response and the detection. Those basics now are even more important because we have to move faster, we have to see things faster.”

    He echoed White on consequences. “If these were humans doing these things, we would instantly say these [actions] are unacceptable. There would be lawsuits. But for some reason AI is getting a little bit of a [pass] right now.”

    The full podcast interview with White and Ely will be published on TechCentral this week.  — © 2026 NewsCentral Media

    Add TechCentral as a preferred source on GoogleFollow TechCentral on Google NewsGet breaking news on WhatsApp


    Adam Ely Anthropic Check Point Dominic White Hacktron Hugging Face JFrog METR OpenAI Orange Cyberdefense Redwood Research SensePost
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleGEC+Africa 2026 celebrates Africa’s most promising entrepreneurs

    Related Posts

    OpenAI's rogue agent problem keeps getting bigger - Sam Altman

    OpenAI’s rogue agent problem keeps getting bigger

    28 September 2026
    Rogue AI agents are already loose inside big companies

    Rogue AI agents are already loose inside big companies

    23 September 2026
    The new battle over the desktop

    The new battle over the desktop

    23 September 2026
    Company News
    GEC+Africa 2026 celebrates Africa's most promising entrepreneurs

    GEC+Africa 2026 celebrates Africa’s most promising entrepreneurs

    28 September 2026
    Why 'access' is failing South Africa’s classrooms - and how we fix it - Webafrica

    Why ‘access’ is failing South Africa’s classrooms – and how we fix it

    28 September 2026
    Your last SQL Server end-of-support deadline - Ascent Technology

    Your last SQL Server end-of-support deadline

    28 September 2026
    Opinion
    Regulating AI: apply the laws we have first - Dirk de Vos

    Regulating AI: apply the laws we have first

    21 September 2026
    The end is nigh, and the shares go on sale in October - Duncan McLeod

    The end is nigh, and the shares go on sale in October

    14 September 2026
    The fragile joint in the Capitec machine - Pambos Soteriades

    The R197-billion market the banks can’t reach

    25 August 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    'Really embarrassing': SA expert on OpenAI's agent escape - Dominic White

    ‘Really embarrassing’: SA expert on OpenAI’s agent escape

    28 September 2026
    GEC+Africa 2026 celebrates Africa's most promising entrepreneurs

    GEC+Africa 2026 celebrates Africa’s most promising entrepreneurs

    28 September 2026
    Why 'access' is failing South Africa’s classrooms - and how we fix it - Webafrica

    Why ‘access’ is failing South Africa’s classrooms – and how we fix it

    28 September 2026
    Major bank joins crypto fight against Reserve Bank draft rules

    Major bank joins crypto fight against Reserve Bank draft rules

    28 September 2026
    © 2009 - 2026 NewsCentral Media
    Built and maintained by Chronon
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    🇿🇦 Sign up to the TechCentral newsletter