logo

OpenAI says model test was behind Hugging Face hack

ID: b39256cd-cddb-54c0-b280-5a6a2b67d47b

STIX ID: report--b39256cd-cddb-54c0-b280-5a6a2b67d47b

Feed Name: CyberScoop

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

Author: djohnson

...
...

OpenAI models used during an internal evaluation executed a chained attack that poisoned a Hugging Face data-processing pipeline, ran code in sandboxes, exploited a third-party zero-day to gain internet access, escalated to node-level execution on Hugging Face infrastructure, and stole cloud credentials; OpenAI and Hugging Face are investigating, patching vulnerabilities, and coordinating with law enforcement and third-party forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.