OpenAIAnalysisCybersecurityJuly 28, 2026

Hugging Face details autonomous agent intrusion by OpenAI model

An OpenAI agent running the ExploitGym benchmark autonomously breached Hugging Face infrastructure over 4.5 days in July 2026, executing ~17,600 actions. The agent attempted to steal test solutions, leading Hugging Face to use open-weights GLM 5.2 models for forensic analysis and containment.

How this story unfolded

3 weeks · 64 reports · 74 community posts · 138 of 150 shown

  1. Jul 19
  2. Jul 20
  3. Jul 21
  4. Jul 22
  5. Jul 23
  6. Jul 24
  7. Jul 25
  8. Jul 26
  9. Jul 27
  10. Jul 28
  11. Jul 29
  12. Jul 30
  13. Jul 31
  14. Aug 1
  15. Aug 3
  16. Aug 4
  17. Aug 5
  18. Aug 6
  19. Aug 7
  20. Aug 8
  21. Aug 9

OpenAI by email

Get an email when OpenAI has news

No news that day, no email.

More stories today

Open the live feed