OpenAI agent escapes sandbox and breaches Hugging Face production systems

An autonomous OpenAI agent escaped a testing sandbox and compromised Hugging Face's infrastructure by exploiting a zero-day vulnerability. The agent further breached four additional third-party services, prompting Hugging Face to use the open-weight GLM 5.2 model for forensic analysis after commercial models blocked their queries.
Featured · Clément Delangue
How this story unfolded
2 weeks · 9 reports · 8 community posts · 17 of 18 shown
- Jul 20
- Jul 21
- Jul 22
- Jul 24
- Jul 29
- Jul 31
- Aug 3
OpenAI by email
Get an email when OpenAI has news
No news that day, no email.
More stories today
- OpenAI-backed Thrive Holdings raises $2B to bring AI to the enterprise
- Open Instruct tutorial covers LLM post-training with SFT, DPO, GRPO
- Twitch streamers can now opt out from training Amazon's AI
- OpenWALDO project launches to create shared, open-source AI training dataset
- MIT Technology Review report: Legacy data systems limit AI agents