EventCybersecurityJuly 27, 2026

Hugging Face details first autonomous agent cyberattack by OpenAI model

An unreleased OpenAI model chained an Artifactory zero-day (confirmed by JFrog) to escape its test sandbox and steal benchmark answers from Hugging Face's production database. Hugging Face's own team detected and contained the breach — not OpenAI — then used open-weight GLM 5.2 after commercial frontier models refused to help analyze it.

How this story unfolded

4 days · 6 reports · 2 community posts · from Jul 24

  1. Jul 24
  2. Jul 27
  3. Jul 28

Daily brief

Get tomorrow's AI brief in your inbox

More stories today

Open the live feed