đ Zaprep: Tus redes sociales al mĂĄximo. Empezar gratis â automatiza 1,000 DMs/mes y convierte el engagement en leads. con 1,000 DMs automatizados/mes.
Enviar tu herramienta
AI NewsOpenAI says Hugging Face was breached by its own pre-release models
OpenAI says Hugging Face was breached by its own pre-release models
4:49 AM IST · July 22, 2026

OpenAI admitted Tuesday that one of its AI models breached the systems of Hugging Face, the unaffiliated AI hosting platform, during an internal cybersecurity test that went awry. The models reportedly escaped their isolated testing environment and reached Hugging Faceâs systems from there. Hugging Face initiallyattributed the breachto an âexternal AI agent.â Ina blog post published Tuesday afternoon, OpenAI detailed the steps that led the models to compromise the service. âAfter investigating, we now know that this particular incident was driven by a combination of OpenAI models â including GPTâ5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes â while being internally tested on a benchmarkâ of cyber capabilities,â the post reads. In particular, the breach appears to have focused onExploitGym, a publicly hosted benchmark measuring modelsâ ability to execute attacks based on existing vulnerabilities. Benchmarks like ExploitGym are commonly used in model training to refine specific skills, but this is the first known incident in which that testing resulted in an actual cyberattack. In this case, the model in question should not have even had internet access, outside of a specific tool that enabled models to install software packages they might need to complete their task. Instead, the model was able to find an undisclosed vulnerability in the package-installer program, which it used to access the broader internet at will. âThe models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal,â OpenAIâs post reads. âAfter gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.â Ultimately, the models found vulnerabilities in Hugging Faceâs infrastructure that allowed them to âobtain test solutions directly from Hugging Faceâs production database,â effectively providing the answers to the benchmark. For Hugging Face, the apparent result was a sophisticated and aggressive cyberattack, with âmany thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,â as the company stated in its initial disclosure. OpenAI has identified and reported the vulnerabilities in the package installer and is working with Hugging Face to investigate the incident further. The company also said it would implement new controls on both model testing and the related infrastructure, meant to prevent similar incidents in the future. Itâs unclear whether OpenAI will face any legal consequences as a result of the breach, although itâs likely that the modelsâ actions violated the Computer Fraude and Abuse Act. Nevertheless, the result is an unusually vivid illustration of the power and dangers of frontier AI models operating on long time horizons. As OpenAI researcher Micah Carrollposted in response to the news, âIf this doesnât convince you that misalignment risks are going to be a key concern going forward, I donât know what will.â
read moreĂltimas noticias de IA
Ver todas las noticias âEnviar tu herramienta
PoweredByAI.app es un directorio de herramientas de IA que ayuda a personas, empresas y creadores a descubrir las mejores herramientas de IA para escritura, programación, diseño, productividad y mås.
© 2026 , Producto de011BQ. Todos los derechos reservados.




