OpenAI and Hugging Face security incident - July 21, 2026

OpenAI and Hugging Face security incident - July 21, 2026 图片 1
OpenAI and Hugging Face security incident - July 21, 2026 图片 2
OpenAI and Hugging Face security incident - July 21, 2026 图片 3
OpenAI and Hugging Face security incident - July 21, 2026 图片 4

Early this week, Hugging Face disclosed a security incident that they believed was carried out by AI agents. 2

Yesterday, OpenAI claimed responsibility.

During an evaluation of a combination of GPT-5.6 Sol and a pre-release model (maybe GPT 6?) on ExploitGym, the models figured out that the best way to beat the benchmark was to break into Hugging Face's database and literally get the test solutions. 1

The evaluation was performed in a sandbox, but the models found and exploited a zero-day vulnerability in the "package registry cache proxy". They then escalated their privileges and moved through OpenAI's internal systems until they found a node with Internet access. Once they had Internet access, they submitted a malicious dataset to Hugging Face that exploited two code-execution paths…

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论