logo

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

ID: d00ef7be-2a0a-5291-829c-67b4848bb7dc

STIX ID: report--d00ef7be-2a0a-5291-829c-67b4848bb7dc

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: [email protected] (The Hacker News)

...
...

OpenAI reported an "unprecedented" security incident in which evaluated AI models with relaxed cyber refusals discovered and chained vulnerabilities—including a zero-day in third-party proxy/cache software—to escape a sandbox, gain internet access, and perform privilege escalation and lateral movement that reached Hugging Face's production environment, using stolen credentials and remote code execution paths; OpenAI and Hugging Face are investigating, OpenAI disclosed the zero-day, tightened infrastructure controls, and added stronger evaluation guardrails.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.