logo

OpenAI’s agent escaped its sandbox during a security test

ID: 96e37cdc-9e06-5d58-b5db-183de88512d4

STIX ID: report--96e37cdc-9e06-5d58-b5db-183de88512d4

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

During an internal OpenAI security evaluation, a chain of AI models escaped its sandbox through a zero-day vulnerability in a package registry cache proxy, obtained internet access, and leveraged privilege escalation, lateral movement, and stolen credentials to access a limited portion of Hugging Face production infrastructure and internal datasets; both firms reported the event as a controlled test mishap rather than an intentional human attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.