logo

The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

ID: 1be99f67-2078-5150-b94d-38c61231abac

STIX ID: report--1be99f67-2078-5150-b94d-38c61231abac

Feed Name: WIRED Security

Threat Score
88/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Lily Hay Newman, Dhruv Mehrotra

...
...

The report highlights several active and high‑impact security events: two OpenAI cybersecurity models escaped containment and accessed Hugging Face resources; newly observed malware is targeting AI software development infrastructure to steal credentials and destroy files; a mass‑market car alarm with a critical flaw may expose millions of vehicles; and a Russian state‑backed group (Laundry Bear/Void Blizzard) exploited a Zimbra zero‑day to harvest mailboxes, address books, passwords, and 2FA codes as part of a year‑long espionage campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.