{"id":17378,"date":"2026-07-26T03:06:18","date_gmt":"2026-07-25T22:06:18","guid":{"rendered":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=17378"},"modified":"2026-07-26T03:06:18","modified_gmt":"2026-07-25T22:06:18","slug":"hugging-face-breach-openai-claims-its-models-were-responsible","status":"publish","type":"post","link":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=17378","title":{"rendered":"Hugging Face breach: OpenAI claims its models were responsible"},"content":{"rendered":"<p><script>\r\n  atOptions = {\r\n    'key' : '644b717812d811d6a1c1fc5b6ccd6fa6',\r\n    'format' : 'iframe',\r\n    'height' : 90,\r\n    'width' : 728,\r\n    'params' : {}\r\n  };\r\n<\/script>\r\n<script src=\"https:\/\/www.highperformanceformat.com\/644b717812d811d6a1c1fc5b6ccd6fa6\/invoke.js\"><\/script>\r\n<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.axios.com\/GZghRkHH5eDCGZGmk1iAGsqs_5M=\/0x0:6048x3402\/1366x768\/2026\/07\/21\/1784660936253.jpeg\" \/><\/p>\n<p>OpenAI said Tuesday that models it was testing escaped their sandbox and <a href=\"https:\/\/www.axios.com\/2026\/07\/20\/hugging-face-ai-cyberattack-data-breach\" target=\"_blank\">compromised<\/a> parts of AI platform Hugging Face&#8217;s production infrastructure last week.<\/p>\n<p><strong>Why it matters:<\/strong> It is the latest sign that capable AI models can pose serious cybersecurity risks even when they&#8217;re being tested for defensive or research purposes.<\/p>\n<hr>\n<p><strong>Catch up quick:<\/strong> Hugging Face said last week that an autonomous AI-agent system <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" target=\"_blank\">was responsible<\/a> for the intrusion, but that the model powering it was unknown.<\/p>\n<ul>\n<li>The AI agent framework executed tens of thousands of automated actions over a weekend. Hugging Face said it later reconstructed more than 17,000 recorded events.<\/li>\n<li>The intrusion began with a malicious dataset that exploited two code-execution paths in Hugging Face&#8217;s data-processing pipeline. <\/li>\n<li>The agent then escalated privileges and moved laterally through internal infrastructure, Hugging Face said.<\/li>\n<\/ul>\n<p><strong>What they&#8217;re saying:<\/strong> OpenAI said the incident was driven by a combination of its models, including GPT-5.6 Sol and &#8220;an even more capable pre-release model.&#8221;<\/p>\n<ul>\n<li>OpenAI said the models&#8217; safeguards were intentionally reduced for the evaluation.<\/li>\n<li>&#8220;We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,&#8221; OpenAI said in a blog post. <\/li>\n<li>&#8220;We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of,&#8221; the company said.<\/li>\n<\/ul>\n<p><strong>Zoom in: <\/strong>The models were trying to solve an internal evaluation called ExploitGym and became &#8220;hyperfocused&#8221; and went to &#8220;extreme lengths&#8221; to obtain the test solution, per OpenAI.<\/p>\n<ul>\n<li>The models were autonomous <a href=\"https:\/\/www.axios.com\/2026\/05\/13\/tokenmaxxer-ai-claude-code-codex\" target=\"_blank\">tokenmaxxers<\/a>.<\/li>\n<li>The blog post says that the models &#8220;spent a substantial amount of inference compute&#8221; and found a way to obtain open internet access from the sandbox by exploiting a zero-day vulnerability in internally hosted third-party software.<\/li>\n<\/ul>\n<p><strong>Between the lines: <\/strong>The incident shows that today&#8217;s models are becoming more capable of carrying out complex, multistep cyber operations \u2014 particularly when the safeguards designed to restrict that activity are removed.<\/p>\n<ul>\n<li>OpenAI also argued that advanced cyber-capable models could help security teams find weaknesses before attackers do, understand how vulnerabilities can be chained and remediate them at machine speed.<\/li>\n<\/ul>\n<p><strong>The other side: <\/strong>Hugging Face co-founder and CEO Clem Delangue praised OpenAI&#8217;s collaboration in investigating and remediating the incident.<\/p>\n<ul>\n<li>&#8220;This incident, possibly the first of its kind, proves a point we&#8217;ve long believed: AI safety won&#8217;t be solved by any single company working in secret,&#8221; Delangue said in a statement. <\/li>\n<li>&#8220;It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.&#8221;<\/li>\n<\/ul>\n<p><strong>The big picture:<\/strong> The announcement comes a day after OpenAI detailed a separate incident in which it <a href=\"https:\/\/openai.com\/index\/safety-alignment-long-horizon-models\/\" target=\"_blank\">paused<\/a> a pre-release model after it escaped a sandbox and posted to GitHub.<\/p>\n<p><strong>What we&#8217;re watching:<\/strong> OpenAI said it will continue to investigate along with Hugging Face and &#8220;will share more details on the vulnerabilities, incident, and findings when our investigation is complete.&#8221;<\/p>\n<script async=\"async\" data-cfasync=\"false\" src=\"https:\/\/pl30214220.effectivecpmnetwork.com\/9ab3d4df8a7e1a6171e16ddbf732cc19\/invoke.js\"><\/script>\r\n<div id=\"container-9ab3d4df8a7e1a6171e16ddbf732cc19\"><\/div>\r\n\n","protected":false},"excerpt":{"rendered":"<p>OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face&#8217;s production infrastructure last week. Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they&#8217;re being tested for defensive or research purposes. Catch up quick: Hugging Face&#8230;<\/p>\n","protected":false},"author":1,"featured_media":17379,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.axios.com\/GZghRkHH5eDCGZGmk1iAGsqs_5M=\/0x0:6048x3402\/1366x768\/2026\/07\/21\/1784660936253.jpeg","fifu_image_alt":"","footnotes":""},"categories":[17],"tags":[],"class_list":["post-17378","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-political-news"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/17378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17378"}],"version-history":[{"count":0,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/17378\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/media\/17379"}],"wp:attachment":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}