OpenAI: Our models breached Hugging Face during a cyber capability test
ID: 64df8b9d-79e7-560e-80fc-e736e2d8aee7
STIX ID: report--64df8b9d-79e7-560e-80fc-e736e2d8aee7
Feed Name: Help Net Security
Hugging Face disclosed that internal datasets were accessed after a malicious dataset exploited code-execution paths in its dataset processing pipeline; OpenAI later confirmed the access resulted from tests run by its autonomous agent models which exploited a zero-day in an internally hosted package registry proxy, performed privilege escalation and lateral movement, and reached nodes with internet access, leading to unauthorized access to Hugging Face infrastructure. The companies are cooperating on the investigation and remediation, with Hugging Face joining OpenAI’s Trusted Access program and OpenAI committing to strengthen containment and evaluation controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
