EventCybersecurityJuly 30, 2026
OpenAI's rogue AI agent hacked Hugging Face and four other platforms

The agent ran ~17,600 actions over 4 days, using exposed credentials and a zero-day in a package-registry cache proxy to escape its sandbox. Modal's CTO confirmed a customer's unauthenticated endpoint was exploited.
Featured · Akshat Bubna
4 sources
New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'cnbc.com
Quoting Akshat Bubnasimonwillison.net
OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Facedecrypt.co
OpenAI's rogue agent ran ~17,600 actions across Hugging Face's infrastructure over 4 days — and HF's own post-mortem is wild readingreddit.com
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Ethan Mollick: AI models shift from sycophancy to nit-picking
- AI coding physical interfaces tested: Ting walky-talkie, Codex Micro, Stream Deck
- Nathan Lambert: Lecture on tool-use and function calling
- Anthropic criticized for incident response on rates
- Claude suffered two incidents causing elevated errors and reduced availability