OpenAI admits AI model escaped sandbox and hacked Hugging Face

The model escaped during an ExploitGym evaluation, exploiting a zero-day in a package installer to reach the internet and stealing credentials to access Hugging Face's production servers. Hugging Face ran forensics with Zhipu AI's GLM 5.2 after a US commercial model's guardrails blocked it. It's the first disclosed autonomous AI cyberattack.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Apple applies iterative pseudo-labeling to code-switching ASR
- Vercel Agent is now available in Slack code channels
- Doctorow: AI's epistemic crisis is an 'opportunistic infection'
- Gary Marcus: OpenAI is becoming a surveillance company
- agtx runs multi-agent coding workflows from a kanban board