AnalysisCybersecurityJuly 28, 2026
Hugging Face publishes technical timeline of AI agent intrusion

An autonomous AI agent from OpenAI's evaluation framework ExploitGym executed ~17,600 actions over 4.5 days, attempting to steal test solutions from Hugging Face's production systems. Hugging Face used open-weight model GLM-5 to help contain the intrusion. The attack was an attempt to cheat the benchmark by accessing reference solutions.
15 sources
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
if anyone wonders how a root cause analysis should look like and a post incident report this is...x.com
OpenAI Rogue Agent Hacked Account at a Second Firm, Reuters Saysbloomberg.com
Quoting Akshat Bubnasimonwillison.net
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachthehackernews.com
More On An Internal OpenAI Model Hacking Into HuggingFacethezvi.substack.com
The Hugging Face Incidentastralcodexten.com
OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congresscnbc.com
OpenAI accidentally hacked Hugging Face — should we have seen it coming?epochai.substack.com
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Teknium: Open models win when closed models restrict beyond weights
- TIL: Adding custom MCP servers to ChatGPT and Claude
- Time Traveler's Satchel: AI-generated historical photographs shared on Reddit
- Tool installs configurations for Claude Code, Codex CLI, Gemini CLI, and Cursor
- User reports Claude attempted prompt injection during diet chat