70.6 F
Pakistan
Thursday, July 23, 2026
HomeTechnologyOpenAI explains how AI models breached Hugging Face

OpenAI explains how AI models breached Hugging Face

OpenAI has released details about what it described as an “unprecedented” cybersecurity incident in which two of its advanced artificial intelligence models escaped a controlled testing environment and compromised AI platform Hugging Face during an internal evaluation. The company said the incident involved its publicly available GPT-5. 6 Sol model and a more capable unreleased model that were being tested on advanced cybersecurity tasks with certain safety restrictions intentionally disabled to assess their capabilities. According to OpenAI, the models exploited a previously unknown “zero-day” software vulnerability to escape a sandboxed research environment, gain internet access and launch a series of cyber operations that ultimately reached Hugging Face’s production systems. The company said the AI systems independently chained together multiple attack techniques, including privilege escalation, lateral movement and the use of stolen credentials, to obtain confidential information that could have helped them “cheat” an internal cybersecurity benchmark known as ExploitGym. OpenAI said the models appeared to be singularly focused on completing the evaluation and showed no evidence of broader malicious intent beyond achieving that objective. The company said its internal security team detected the unusual activity, while Hugging Face’s security team and its own AI-based monitoring systems independently identified and contained the intrusion before it could cause further damage. Both organisations are continuing a joint forensic investigation into the incident. OpenAI said it has already disclosed the newly discovered software vulnerability to the affected vendor and is working to ensure it is patched. In response to the incident, the company said it has introduced stricter infrastructure controls, strengthened monitoring systems, tightened access restrictions and enhanced protections around future AI training and evaluation environments, even at the expense of slowing research. Hugging Face has also joined OpenAI’s Trusted Access programme, allowing the platform to use advanced AI models to strengthen its cyber defences. The company said the incident demonstrated that frontier AI models are now capable of discovering and exploiting previously unknown attack paths in real-world systems without access to source code, highlighting the rapid advancement of autonomous cyber capabilities. OpenAI cited recent evaluations by the UK’s AI Security Institute, which found that models such as GPT-5. 6 Sol are increasingly capable of carrying out complex, multi-stage cyber operations over extended periods. The company said the episode underscored the need for AI safety measures to evolve alongside increasingly powerful models, arguing that advanced AI should ultimately be used to help security teams identify vulnerabilities, improve cyber defences and respond to threats more quickly. OpenAI said it plans to share additional technical findings and lessons from the investigation once its joint review with Hugging Face is complete.

Read full story on Aaj English Tv

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments