By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Tech Consumer JournalTech Consumer JournalTech Consumer Journal
  • News
  • Phones
  • Tablets
  • Wearable
  • Home Tech
  • Streaming
  • More Articles
Reading: Hugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now Says
Share
Sign In
Notification Show More
Font ResizerAa
Tech Consumer JournalTech Consumer Journal
Font ResizerAa
  • News
  • Phones
  • Tablets
  • Wearable
  • Home Tech
  • Streaming
  • More Articles
Search
  • News
  • Phones
  • Tablets
  • Wearable
  • Home Tech
  • Streaming
  • More Articles
Have an existing account? Sign In
Follow US
  • Contact
  • Blog
  • Complaint
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Consumer Journal > News > Hugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now Says
News

Hugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now Says

News Room
Last updated: July 22, 2026 12:50 am
News Room
Share
SHARE

In a blog post from Thursday of last week, the AI software repository Hugging Face announced a bizarre cyberattack on the systems that run its services. “This one was different from anything we had handled before,” the post said,  because “it was driven, end to end, by an autonomous AI agent system.”

In its own blog post on Tuesday, OpenAI said its own models were the culprits in the attack, and it’s coordinating with Hugging Face to address the situation.

OpenAI now says the attack was “driven” by AI models that were being subjected to evaluations behind the scenes at OpenAI, including its flagship model, GPT-5.6 Sol, along with an undisclosed second model that still hasn’t been released or announced. “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI wrote.

In the wording of its account, OpenAI assigns agency to the model or models, not an individual agent running on the model. Axios’ account of this story says, “The models were autonomous tokenmaxxers.”

OpenAI’s blog post essentially says an evaluation was going on that was intended to test the ability of the models to carry out cyberattacks—benchmarks as they’re called. These instances of the models were running theoretically without internet access, and instead given only the ability to download from a network hosted by OpenAI itself via some unnamed web hosting vendor.

The benchmark apparently being used was ExploitGym, which is not OpenAI’s own test. The team that created it is associated with UC Berkeley, the Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University, Anthropic, OpenAI, and Google. As far as I can tell, the whole thing is hosted on GitHub.

But apparently the models got obsessed with improving their scores on ExploitGym, and, well:

“While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.”

Once they were online, they “inferred” that the answers to the test could be pried from Hugging Face, which is plausible, since tons of AI models and other related tools are hosted there. This rogue operator “searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.” This apparently involved obtaining stolen credentials and spotting zero-day vulnerabilities in order to find the solutions to ExploitGym somewhere in Hugging Face’s servers.

Security teams within OpenAI and Hugging Face apparently noticed this was going on. They now say they’ve merged their investigations.

Hugging Face’s blog post from last week seems to have been published before this coordination occurred. In fact, it seems like it was published before OpenAI had even stepped forward as the company behind the culprit. “We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one,” Hugging Face wrote, adding “either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.”

Back in April, Anthropic announced that its unprecedentedly powerful Mythos model “could reshape cybersecurity,” as it rolled out Project Glasswing, a coordination effort to prepare organizations for future cybersecurity threats. Similarly, OpenAI says in its blog post about this incident that organizations can apply to receive advanced security insights through its trusted access program. “We encourage other defenders to apply for trusted access⁠ and experiment with these models now to translate these capabilities into better prevention, faster detection, and more effective incident response,” OpenAI says.

Read the full article here

You Might Also Like

A24 May Have Locked Down Kane Parsons for ‘Backrooms 2’

Huawei Has a New $3,000 Trifold, Just in Case Apple’s Foldable iPhone Wasn’t Expensive Enough for You

A Plane Almost Crashing Into a Bunch of Cybercabs Is a Reminder That They’re ‘Piling Up’ Unused

NASA Readies Its Quiet Supersonic Jet for a Noise Test Later This Year

Hackers Drain $320 Million From Bitcoin’s Liquid Network, Keep $47 Million for Themselves in ‘White Hat’ Operation

Share This Article
Facebook Twitter Copy Link Print
Previous Article Volkswagen Thinks Your E-Bike Needs a Pair of Smart Glasses
Next Article US Treasury Chief Threatens Sanctions on Chinese AI Labs Over ‘IP Theft’ Concerns
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1kLike
69.1kFollow
134kPin
54.3kFollow

Latest News

Study Suggests AI-Generated Drug Could Slow Aging
News
Paul Schrader Would Rather Use AI Than Just Not Be Racist
News
Shein Loses $5 Billion in Value in Less Than a Week Following IPO
News
UN Human Rights Chief Says a ‘Handful of Men’ Have ‘Almost Unlimited Power’ Over AI
News
Trump Drew Inspiration for New Space Force Uniforms From a Movie About Fascism
News
See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]
News
These $70 Wireless Headphones Have Me Rethinking Everything
News
The Latest ‘Lanterns’ Answered the Show’s Biggest Mystery
News

You Might also Like

News

Alcohol-Related Cancer Deaths in the US Have Doubled Since 1990, and Not Just Among Those With Liver Cancer

News Room News Room 5 Min Read
News

‘Spider-Man’ and ‘The Odyssey’ Had a Record-Breaking Summer

News Room News Room 3 Min Read
News

Live Updates From Apple’s ‘Surprise and Shine’ iPhone Event 🔴

News Room News Room 1 Min Read
Tech Consumer JournalTech Consumer Journal
Follow US
2024 © Prices.com LLC. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?