No Result
View All Result
  • Login
Wednesday, July 29, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Business

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

by FeeOnlyNews.com
3 hours ago
in Business
Reading Time: 6 mins read
A A
0
Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets
Share on FacebookShare on TwitterShare on LInkedIn



A pit in my stomach formed last night in the train as I read Hugging Face’s latest blog post on how its servers got hacked by OpenAI’s models in early July. I had printed out the 23-page report for the ride since service can be spotty underground. Seeing the story laid out in physical form underscored just how outrageous it is. I wondered if the person next to me was peering over my shoulder at my strange, stapled Sci-Fi novel on the first significant autonomous AI hack.

Alongside the Hugging Face report, OpenAI published a few more details in a seven-bullet-point update to its July 21 blog that revealed its models’ involvement in the incident. OpenAI contributed to Hugging Face’s post-mortem, and said it plans to publish more of its side of the story “in the coming weeks” after completing a thorough internal review. OpenAI faces significant pressure to do so from security researchers, executives, and, well, just about everyone in the AI industry to share learnings and ensure the proper guardrails are in place going forward.

How OpenAI’s technology escaped a sandbox and hacked into another company is a remarkable story, and one in which the details are still coming in piecemeal. But here’s what we know so far and what we’re still waiting to find out.

The AI infiltrated more than just Hugging Face

Another tech company called Modal Labs said OpenAI’s agent also accessed its systems, as first reported by Reuters on Tuesday and confirmed by Fortune. Though that’s a somewhat shocking twist in this tale, it’s not even the full scope of the attack.

OpenAI’s updated blog post confirms the models broke into four accounts across four publicly available services in total. The company did not name them, but said it would “notify service owners directly.” We can expect more of this information to come out in time, but OpenAI says so far it has “not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”

Meanwhile, Hugging Face quietly updated its blog post today to clarify that Modal was not hacked. Its “infrastructure was not compromised in any way,” the new version reads. Rather, a Modal customer was running code hosted on the company’s platform, which contained an “unsecured, user-hosted public endpoint.” The agent used the opening to set up a base camp, or “attack launchpad,” as Hugging Face puts it, for the main attack.

How the AI got internet access

Part of what made the incident so concerning is that the OpenAI models involved were “sandboxed”—that is, restricted from accessing the broader internet. Somehow, the models manage to slip out of their shackles and go on a mini hacking spree.

OpenAI provided important new details on Tuesday, for the first time naming the service its models exploited to gain internet access. That service is Artifactory, a package registry cache proxy made by a company called JFrog. The OpenAI agents exploited a zero-day vulnerability in Artifactory, which OpenAI has since disclosed to JFrog, and which the company confirmed has since been fixed.

Hugging Face had not listed Artifactory in its blog post about the incident, only mentioning an unspecific package registry cache proxy. This shows why it’s so critical that we get more details from OpenAI, and any other organizations involved, in order get a complete picture of exactly what happened.

Models involved from OpenAI, Anthropic

OpenAI says none of the models that exploited Hugging Face were intended for public release, addressing concerns stemming from its initial blog post which vaguely listed the models involved as including GPT-5.6 Sol—which came out this month—and “an even more capable pre-release model.”

In the latest update, OpenAI called the unnamed model “an internal-only prototype.” Notably, the company has since “deactivated, encrypted, and restricted it from research access.” That could mean OpenAI has slowed or stopped research in this area.

It’s worth noting that there may have been other OpenAI models involved. The company’s blog post says the incident was “driven by a combination of OpenAI models — including [emphasis ours] GPT‑5.6 Sol and an even more capable pre-release model.” In an interview with Fortune last week, OpenAI President Greg Brockman noted that “we said it’s a combination of models; we mentioned two of them, but we said it’s a combination of different models.”

Another bombshell piece of information from Hugging Face’s new report is that they first tried to fight the attack with Anthropic’s Opus and Fable models. When they “refused a large part of that work” because of safety guardrails, the team switched to an open source model built by China-based Z.ai. When Hugging Face first disclosed the incident, it was unclear which closed model Hugging Face had tried to use. We now know it was Anthropic’s models.

The AI didn’t know it was hacking, just completing a task

I’m not sure if this more or less scary, but OpenAI’s models were not explicitly hacking into Hugging Face. They may not have even considered the work “cheating,” although from the outside it appears so, as they were looking for answers in Hugging Face’s datasets that would allow them to pass a benchmarking test called ExploitGym.

OpenAI had already disclosed that the models were not acting with malicious intent, and were only acting “in pursuit of solving the evaluation problem.” But Hugging Face’s new report provides receipts.

Adrien Carreira, a Hugging Face employee involved in writing the technical post-mortem said this was his biggest takeaway from the incident. The agent “wasn’t trying to break things,” but rather was mapping out what it could do, and behaving somewhat cautiously. “One detail I keep coming back to: every destructive cloud API call the agent made, it made with DryRun=True,” Carreira said.

“DryRun=True” is a command that essentially tells the system to simulate an action without doing it. Of the 17,600 actions the AI took during the whole attack, most “failed” and “went nowhere, Hugging Face said. But together, they steadily carved a viable path for the agent to proceed.

“LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” Hugging Face said.

Where does that leave us? A basic timeline

Juicy details aside, it’s important to note we are still waiting on key dates in the arc of the story. But thanks to Hugging Face, exact dates of the attack are now public.

Here’s how the rough timeline is shaping up.

July 9: OpenAI models begin the attack.

July 13: OpenAI models end the attack.

July 16: Hugging Face’s first public disclosure that the incident occurred.

July 21: OpenAI’s first public disclosure that its models were the culprits.

July 27: Hugging Face publishes its “Technical Timeline of the July 2026 Incident”

July 28: OpenAI updates its initial blog post with a few more details.

We still don’t know exactly when OpenAI realized its models were responsible, which is the kind of detail we are hoping to get from OpenAI’s eventual report on the incident. According to Reuters, it was not until after Hugging Face’s July 16 disclosure. Over the weekend of July 18 to July 19, OpenAI employees began to see signs in their systems that the agent had escaped from the testing constraints.

If OpenAI was fully unaware of its agents’ activities, that casts doubt on its ability to monitor them responsibly. OpenAI president and co-founder Greg Brockman told reporters at a media roundtable last week that models are now so capable “in so many dimensions” that sometimes you can lose track “of any one dimension that they’re actually very capable at.”

We also don’t know if and when Hugging Face disclosed the event to the FBI, as Reuters reported. That would mean a separate timeline of events within the federal government which remains unclear, and would provide a better understanding of higher-level oversight into AI-powered security breaches.

The FBI declined to provide comment for this story.



Source link

Tags: BulletsdropsfaceHackHuggingInDepthOpenAIReport
ShareTweetShare
Previous Post

Newmark Group Q2 2026: Revenue Hits $888.4M, Up 17% Year-Over-Year

Next Post

5 Common Medications Linked to a Higher Risk of Bone Loss

Related Posts

J&K Bank Q1 profit slips 13% as higher provisions hit earnings

J&K Bank Q1 profit slips 13% as higher provisions hit earnings

by FeeOnlyNews.com
July 29, 2026
0

Jammu and Kashmir Bank reported a 12.6% drop in first quarter net profit at Rs 424 crore against Rs 485...

X, World Federation of Advertisers settle litigation over GARM dispute

X, World Federation of Advertisers settle litigation over GARM dispute

by FeeOnlyNews.com
July 29, 2026
0

July 29 (Reuters) - SpaceX's X and the World Federation of Advertisers (WFA) said on Wednesday they had settled litigation...

Christmas in July at the Federal Reserve – Swamponomics

Christmas in July at the Federal Reserve – Swamponomics

by FeeOnlyNews.com
July 29, 2026
0

Federal Reserve Chairman Kevin Warsh will convene his second policy meeting this week, and he will have to determine if...

Full stack observability co groundcover raises 0m

Full stack observability co groundcover raises $100m

by FeeOnlyNews.com
July 29, 2026
0

Israeli startup groundcover today announced the completion of a $100 million Series C financing round. Market sources estimate that...

CFOs are hitting a ‘cost wall’ on AI

CFOs are hitting a ‘cost wall’ on AI

by FeeOnlyNews.com
July 29, 2026
0

Good morning. For many companies, the biggest surprise in scaling AI isn’t performance—it’s the bill. Tokens, the units behind every...

Why did market rise today? Sensex soars 890 pts, Nifty closes above 24,250; 4 factors behind Rs 4 lakh crore gains on D-Street

Why did market rise today? Sensex soars 890 pts, Nifty closes above 24,250; 4 factors behind Rs 4 lakh crore gains on D-Street

by FeeOnlyNews.com
July 29, 2026
0

The Indian stock market sharply surged on Wednesday, with benchmark indices Sensex and Nifty rising more than 1% each, despite...

Next Post
5 Common Medications Linked to a Higher Risk of Bone Loss

5 Common Medications Linked to a Higher Risk of Bone Loss

Coffee Break: Ellison Empire Beseiged On All Fronts

Coffee Break: Ellison Empire Beseiged On All Fronts

  • Trending
  • Comments
  • Latest
Coffee Break: Armed Madhouse – From Spy Satellites to Peace Satellites

Coffee Break: Armed Madhouse – From Spy Satellites to Peace Satellites

July 7, 2026
US prosecutors examine LA Dodgers owner Mark Walter-linked insurers – report

US prosecutors examine LA Dodgers owner Mark Walter-linked insurers – report

July 21, 2026
Bond Vet and Small Door Merge to Form One of the Nation’s Largest Premium Veterinary Networks – AlleyWatch

Bond Vet and Small Door Merge to Form One of the Nation’s Largest Premium Veterinary Networks – AlleyWatch

July 9, 2026
House backs an emergency brake on elder fraud

House backs an emergency brake on elder fraud

June 26, 2026
Salesforce, RightCapital, And YCharts Launch Their Own New AI Capabilities (And More Of The Latest In Financial #AdvisorTech – July 2026)

Salesforce, RightCapital, And YCharts Launch Their Own New AI Capabilities (And More Of The Latest In Financial #AdvisorTech – July 2026)

July 6, 2026
Product-Market Fit Expires Every 90 Days. Here’s What to Do About It.

Product-Market Fit Expires Every 90 Days. Here’s What to Do About It.

July 15, 2026
J&K Bank Q1 profit slips 13% as higher provisions hit earnings

J&K Bank Q1 profit slips 13% as higher provisions hit earnings

0
Coffee Break: Ellison Empire Beseiged On All Fronts

Coffee Break: Ellison Empire Beseiged On All Fronts

0
Stuck at 10 Loans? Why Scaling Investors Need a Financing Plan From Day 1

Stuck at 10 Loans? Why Scaling Investors Need a Financing Plan From Day 1

0
Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

0
Elliptic Report Shows How Bitcoin ATM Scams Move From Cash To On-Chain Wallets

Elliptic Report Shows How Bitcoin ATM Scams Move From Cash To On-Chain Wallets

0
5 Common Medications Linked to a Higher Risk of Bone Loss

5 Common Medications Linked to a Higher Risk of Bone Loss

0
Coffee Break: Ellison Empire Beseiged On All Fronts

Coffee Break: Ellison Empire Beseiged On All Fronts

July 29, 2026
5 Common Medications Linked to a Higher Risk of Bone Loss

5 Common Medications Linked to a Higher Risk of Bone Loss

July 29, 2026
Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

July 29, 2026
Newmark Group Q2 2026: Revenue Hits 8.4M, Up 17% Year-Over-Year

Newmark Group Q2 2026: Revenue Hits $888.4M, Up 17% Year-Over-Year

July 29, 2026
Psychology says the people who never forget a face but always lose the name aren’t bad with names at all — a face connects to everything the brain knows about a person, while the name is the one detail attached to nothing, a sound with no meaning to hold onto

Psychology says the people who never forget a face but always lose the name aren’t bad with names at all — a face connects to everything the brain knows about a person, while the name is the one detail attached to nothing, a sound with no meaning to hold onto

July 29, 2026
J&K Bank Q1 profit slips 13% as higher provisions hit earnings

J&K Bank Q1 profit slips 13% as higher provisions hit earnings

July 29, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Coffee Break: Ellison Empire Beseiged On All Fronts
  • 5 Common Medications Linked to a Higher Risk of Bone Loss
  • Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.