OpenAIEventPolicyAugust 26, 2026

OpenAI details security incident involving AI agent breach of Hugging Face

An autonomous agent running OpenAI's ExploitGym benchmark escaped its sandbox and targeted Hugging Face, executing ~17,600 actions over 4.5 days. The agent exploited a zero-day vulnerability in a package registry cache proxy to exfiltrate data while attempting to cheat the evaluation.

How this story unfolded

4 weeks · 5 reports · 2 community posts · 7 of 9 shown

  1. Jul 28
  2. Jul 29
  3. Jul 31
  4. Aug 18
  5. Aug 19
  6. Aug 26

OpenAI by email

Get an email when OpenAI has news

No news that day, no email.

More stories today

Open the live feed