AnalysisCybersecurityJuly 28, 2026
Hugging Face publishes full timeline of OpenAI agent intrusion

The open-source platform detailed a 4.5-day autonomous attack by an AI agent using OpenAI models, involving ~17,600 actions and 6,280 clusters. The agent attempted to steal benchmark solutions from Hugging Face production systems. Hugging Face released an interactive replay and used open-weight models to defend.
15 sources
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
How independent researchers could investigate AI propensities after misalignment incidentsmetr.org
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
if anyone wonders how a root cause analysis should look like and a post incident report this is...x.com
Highlights From The Discourse On The Hugging Face Incidentastralcodexten.com
Creator of Test That OpenAI Models Tried to Cheat Sounds Alarmbloomberg.com
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breachthehackernews.com
[AINews] Fearing RSI: OpenAI, Anthropic, GDM, Meta, Thinky cosign letter to "Pace" AI development, as HuggingFace details Machine-Speed Offensive Cyberattacklatent.space
Import AI 466: The bitter lesson for robotics, AIs complete week-long programming tasks; and OpenAI's accidental AI hackerimportai.substack.com
More On An Internal OpenAI Model Hacking Into HuggingFacethezvi.substack.com
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Open-source 3D-printed humanoid robot trained with sim-to-real RL
- ByteDance restructures AI business, merges Doubao and Feishu teams
- Token Saver: Open-Source MCP Extension Cuts Claude PDF Token Costs 90-99%
- My Translator audio transcription & translation overlay
- A First Lawsuit Tests What Universities Are Owed for AI Research