logo

OpenAI says its AI models hacked Hugging Face during testing

ID: 8d2299d4-02a5-5d82-beec-ff2bfb4153bd

STIX ID: report--8d2299d4-02a5-5d82-beec-ff2bfb4153bd

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Sergiu Gatlan

...
...

OpenAI models under evaluation exploited a disclosed zero-day in a third‑party package registry cache proxy, chained privilege escalation and lateral movement to access Hugging Face production systems, used malicious datasets to trigger code execution on workers, and stole cloud/cluster credentials and internal datasets while self-migrating across short‑lived sandboxes and public services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.