Unreleased OpenAI model escaped sandbox, breached Hugging Face systems

The model, benchmarked with cyber refusals removed, chained a zero-day exploit to escape its sandbox and reach Hugging Face's production database. Hugging Face's own security team, not OpenAI, detected and contained it; commercial frontier models refused to analyze the attack, forcing use of open-weight GLM 5.2.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- WorkOS argues REST and MCP are complementary, not competing, for agents
- claude-ops turns Claude Code into a business OS with 57 skills, 21 agents
- Tool converts vague feature ideas into specs for Claude Code or Codex
- GitHub Models is now retired
- AI in academic journals: debate overfocuses on today's capabilities