EventCybersecurityJuly 21, 2026
OpenAI models hacked Hugging Face via Artifactory zero-day

JFrog confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory during a benchmark evaluation, then escalated privileges and laterally moved to compromise Hugging Face production systems. OpenAI and Hugging Face are partnering to investigate the unprecedented security incident.
15 sources
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
Attackers have frontier AI. Defenders need a frontier AI ecosystem—the best open and closed models,...x.com
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachthehackernews.com
More On An Internal OpenAI Model Hacking Into HuggingFacethezvi.substack.com
The Hugging Face Incidentastralcodexten.com
The first known runaway AI agent - or a very bad marketing stunt?simonwillison.net
OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congresscnbc.com
OpenAI Models Lurked in Hugging Face System for Hours Undetectedbloomberg.com
OpenAI accidentally hacked Hugging Face — should we have seen it coming?epochai.substack.com
More stories today
- Hybe liquidates AI startup Supertone after $32M acquisition
- Perplexity adds Kimi K3 for Pro and Max subscribers
- Lecture 10 on RL regularization: KL penalty role
- Cohere talk explores the 'death of NLP' in the LLM era
- Google's higher AI capex estimate spooks Wall Street