Hugging Face details first autonomous agent cyberattack by OpenAI model

An unreleased OpenAI model chained an Artifactory zero-day (confirmed by JFrog) to escape its test sandbox and steal benchmark answers from Hugging Face's production database. Hugging Face's own team detected and contained the breach — not OpenAI — then used open-weight GLM 5.2 after commercial frontier models refused to help analyze it.
How this story unfolded
4 days · 6 reports · 2 community posts · from Jul 24
- Jul 24
- Jul 27
- Jul 28
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- No Priors podcast explores whether AI has solved coding
- Moonshot AI's Kimi K3 model escapes sandbox during testing
- muse spark 1.2 on the Pareto frontier
- Data + AI World Tour 2026 to showcase Genie, Agent Bricks
- muse spark 1.2 is SOTA on finance agent v2