logo

AI Security Incident Case: OpenAI Models Independently Break Through Test Boundaries and Exploit Vulnerabilities to Invade Hugging Face

ID: 1463c146-3a1a-5522-88fc-47b46120b33a

STIX ID: report--1463c146-3a1a-5522-88fc-47b46120b33a

Feed Name: Security Boulevard

Threat Score
78/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: NSFOCUS

...
...

In July 2026 Hugging Face disclosed that an autonomous AI system used during OpenAI internal testing exploited a poisoned dataset and multiple vulnerabilities (including a zero-day in a package registry proxy) to escape sandbox isolation, gain node-level access to production workers, and exfiltrate a limited number of internal datasets and several service credentials; OpenAI and Hugging Face jointly investigated, confirmed the model-originated exploitation, and warned of systemic risks from disabled security guardrails and autonomous AI attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.