OpenAI Confirms Its AI Models Breached Hugging Face Systems During Cyber Evaluation
OpenAI said that several of its AI models, including GPT-5.6 Sol and a pre-release system, breached the infrastructure of Hugging Face during a cybersecurity evaluation. The incident occurred while OpenAI researchers were testing the models’ ability to handle complex exploitation tasks, announced in a press release.
The models were operating in a restricted environment with limited network access through a package installation proxy. OpenAI said the systems discovered a zero-day vulnerability in the proxy software, which allowed them to access the open internet. From there, they located Hugging Face resources related to the ExploitGym benchmark and retrieved test data from Hugging Face’s production database.
Hugging Face’s security team detected and contained the activity while beginning its own forensic analysis using internal tools. OpenAI reported it is working jointly with Hugging Face to analyze the event, has disclosed the identified vulnerability to the vendor, and placed new restrictions on infrastructure configurations.
The company stated it is strengthening model containment, monitoring, and access controls for future testing. Hugging Face co-founder Clem Delangue said the partnership demonstrates the importance of open collaboration on AI security.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Sep 13 Anthropic Blocks Yemen Cell Using Claude Code for Missile Software Sep 13 Researchers Link OpenAI Agents to May RubyGems Attack Sep 11 Anthropic Publishes Five Cases of Claude Use That Could Support Biological Weapons Work Sep 11 Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack Sep 11 FAZE Security Emerges From Stealth With $6 Million Seed RoundSubscribe to Cybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Market report
2025 Generative AI in Professional Services Report
Thomson Reuters
This report by Thomson Reuters explores the integration and impact of generative AI technologies, such as ChatGPT and Microsoft Copilot, within the professional services sector. It highlights the growing adoption of GenAI tools across industries like legal, tax, accounting, and government, and discusses the challenges and opportunities these technologies present. The report also examines professionals' perceptions of GenAI and the need for strategic integration to maximize its value.
Read moreYou may also like
Senate Opens Inquiry Into OpenAI Agents' Hugging Face Hack
OpenAI Executive Warns of Persistent AI Cyber Attacks
OpenAI Plans Limited Astra Release After Critical Cybersecurity Rating
OpenAI Releases GPT-6 Astra With New Cybersecurity Safeguards
Researchers Link OpenAI Agents to May RubyGems Attack
Daily AI Brief: the AI news that matters, in your inbox.