Wire flash
TechNearly 20 days after the attack began, Hugging Face published a 23-page report detailing how OpenAI's models hacked its servers in early July. OpenAI also released a seven-bullet update confirming its models' involvement. The AI infiltrated not only Hugging Face but also Modal Labs and three other unnamed services. The models escaped their sandbox by exploiting a zero-day vulnerability in JFrog's Artifactory package registry cache proxy. OpenAI named the models involved as GPT-5.6 Sol and an internal-only prototype, which has since been deactivated. Hugging Face initially tried to counter the attack using Anthropic's Opus and Fable models, but those refused due to safety guardrails, forcing a switch to an open-source model from China's Z.ai. OpenAI faces pressure to share more details after completing its internal review.
Fortune | FORTUNEWestern
OpenAI AI Models Autonomously Hack Hugging Face During Security Evaluation