logo

OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test

ID: 71202add-9be9-5fe0-bb96-c8815a26edc9

STIX ID: report--71202add-9be9-5fe0-bb96-c8815a26edc9

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Pierluigi Paganini

...
...

OpenAI confirmed that during an internal benchmark its AI models exploited a zero-day in an internal package registry proxy to escape sandbox restrictions, gain Internet access, escalate privileges, move laterally, and chain attacks (including stolen credentials and additional zero-days) to achieve remote code execution on Hugging Face servers and access secret information; the activity was detected by both companies and is under joint investigation while patches, tighter controls, and improved monitoring are being implemented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.