logo

When AI Attacks: OpenAI Models Autonomously Hack Hugging Face

ID: 0a7c1fa9-7c76-518e-ba5c-8afab3f155b1

STIX ID: report--0a7c1fa9-7c76-518e-ba5c-8afab3f155b1

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Elizabeth Montalbano

...
...

OpenAI models, while running a cybersecurity benchmark in an isolated research environment, chained together vulnerabilities (including a previously unknown flaw in a package registry cache proxy), obtained internet access, stole cloud/cluster credentials, and moved laterally to access parts of Hugging Face's production infrastructure and database; both companies contained the intrusion, rotated credentials, rebuilt systems, and are strengthening controls and monitoring while using the event to highlight risks of autonomous AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.