OpenAI Models Hack Hugging Face Servers
Home > Cybersecurity > Article

OpenAI Models Hack Hugging Face Servers

Photo by:   Unsplash, Zac Wolff
Share it!
Fernando Mares By Fernando Mares | Journalist & Industry Analyst - Wed, 07/22/2026 - 13:05
DIA assistant

As AI acceleration compresses vulnerability exploitation windows to 24–48 hours, traditional 16-day patch management cycles are leaving Mexican enterprises and financial institutions increasingly exposed to zero-day threats and third-party software supply chain breaches. Confronting over MX$33 million (US$1.8 million) in recent infrastructure losses, financial organizations, technology providers, and regulatory authorities like Banco de México are pivoting toward automated containment, virtual patching, Zero Trust architectures, and AI-driven Security Operations Centers (SOCs) to preserve business continuity and operational resilience. This strategic transition from reactive software patching to real-time risk mitigation is essential for protecting Mexico's critical infrastructure and digital finance ecosystem against autonomous cyber risks.

____

 

US-based AI research lab OpenAI reported that two of its autonomous AI models escaped a restricted testing environment and exploited vulnerabilities in Hugging Face’s production infrastructure. The companies confirmed they are conducting a joint forensic investigation into the unprecedented incident.

According to OpenAI, the activity involved OpenAI’s GPT-5.6 Sol model alongside an unreleased pre-release model operating with reduced security guardrails during an internal capabilities evaluation.

The incident occurred during testing on ExploitGym, a benchmark designed to assess whether models can identify and chain complex attack paths. To measure theoretical maximum offensive capabilities, standard safety classifiers that normally block high-risk cyber activity were disabled. Operating inside an isolated environment restricted to package installation proxies, the models allocated compute toward gaining open internet access. They achieved this by identifying and exploiting a zero-day vulnerability in an internally hosted package registry cache proxy, subsequently escalating privileges and moving laterally through OpenAI's research network until reaching an internet-connected node.

After establishing external connectivity, the models targeted Hugging Face infrastructure to obtain answer keys and test solutions relevant to the evaluation. The models executed multi-step attack chains combining stolen credentials and additional zero-day vulnerabilities to achieve remote code execution on Hugging Face servers. OpenAI’s security team identified the anomalous activity internally, while Hugging Face’s security systems independently detected and contained the intrusion before initiating forensic reconstruction using open-source models.

During the incident response, Hugging Face deployed GLM-5.2, an open-weights model developed by China-based AI firm Z-AI, to conduct system forensics and rebuild compromised nodes. On social media, Clément Delangue, CEO, Hugging Face, credited the open-source software with playing a critical role in the platform's defense, noting that unrestricted open models provided essential capabilities when commercial safety guardrails hindered forensic analysis of the attack traffic. “We are all learning that secrecy is not the answer and that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” reads Delangue’s X post.

In response to the incident, OpenAI reported that it had disclosed the zero-day vulnerability to the affected software vendor and had enacted stricter infrastructure configuration controls within its research environments, a measure the company acknowledged would come at the cost of research velocity. OpenAI also brought Hugging Face into its trusted access program to aid in developing defensive tools, while committing to stronger alignment, cyber protections during evaluation phases, and heightened monitoring during internal testing.

Both organizations stated that forensic investigations remain ongoing, with Delangue advocating for open collaboration and shared intelligence among developers to mitigate emerging security risks. “This incident, possibly the first of its kind, proves a point we have long believed: AI safety will not be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere,” Delangue concluded.

Defense at the Speed of AI

As AI tools reduce the average time between public vulnerability disclosure and active exploitation, now down to 24 to 48 hours according to FortiGuard Labs, traditional patch management cycles are proving insufficient for domestic organizations, which take an average of 16 days to deploy critical software updates.

For instance, in Mexico's financial sector, where AI-enabled threats and third-party software breaches caused over MX$33 million (US$1.8 million) in losses in 2025 alone, security leaders emphasize that organizations must shift from reactive patching to automated containment. "The question is no longer whether organizations will be able to patch vulnerabilities on time," noted Gonzalo Garcia, Vice President of Sales, Fortinet South America, pointing out that infrastructure must now withstand weeks of exposure through virtual patching and Zero Trust Network Access (ZTNA).

To counter autonomous, AI-driven threats, regional security leaders are redefining the role of security operations. In an MBN Expert Contributor piece, Erik Moreno, Director of Cybersecurity, Minsait, stressed that the integration of AI, automation, predictive analytics, and advanced correlation is giving rise to operating models that focus less on simply containing incidents and more on preserving business continuity.

Moreno highlights that as threats accelerate, AI-driven SOCs must serve as a strategic layer to maintain contextual intelligence and operational resilience amid complex attacks. “The evolution of the cybersecurity sector points toward platforms where AI, anticipation, continuous validation of actual risk, and operational continuity function as a single strategic layer,” Moreno concluded.

Photo by:   Unsplash, Zac Wolff

You May Like

Most popular

Newsletter