❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 22 July 2026Main stream

How OpenAI’s human mistake led to the AI-powered hack on Hugging Face

22 July 2026 at 15:11
OpenAI made a mistake setting up what it called a β€œhighly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible.

OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face

22 July 2026 at 12:47

OpenAI says an agent powered by its LLM models escaped its sandboxed testing environment to infiltrate Hugging Face's servers as part of an overzealous attempt to obtain solutions to a benchmark test. The company says it considers the unintended infiltration an "an unprecedented cyber incident" and is working with Hugging Face on new protections to prevent a recurrence.

Hugging Face disclosed an intrusion last week that it said involved "unauthorized access to a limited set of internal datasets and to several credentials used by our services." The AI data clearinghouse said it used its own LLM-driven analysis to identify "a swarm of tens of thousands of automated actions" from an "autonomous agent framework." That agentic swarm exploited a flaw in Hugging Face's data-processing pipeline to gain the ability to run code as a processing worker, eventually escalating to high-level access to the company's cloud and server clusters.

At the time, Hugging Face said the LLM being used in the attack was "still not known." But OpenAI took responsibility for the intrusion Tuesday evening, saying it came about during an internal test involving the recently released GPT-5.6 Sol and "an even more capable pre-release model." The models were being tested against the ExploitGym benchmark, an independent testing suite based on hundreds of real-world security vulnerabilities.

Read full article

Comments

Β© Getty Images

OpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceΒ 

22 July 2026 at 03:48

OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality.

The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging FaceΒ  appeared first on SecurityWeek.

Before yesterdayMain stream

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

By: Waqas
20 July 2026 at 17:06
An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering.

Hugging Face’s CEO on why companies are done renting their AI

10 July 2026 at 10:00
Open source AI is booming, according toΒ Hugging FaceΒ CEOΒ Clem Delangue. The company has grown into something like a GitHub for AI in recent years, where AI builders can share and download open models and datasets, now used by roughly half the Fortune 500. Delangue has seen the same story play out again and again: companies start […]
❌
❌