OpenAI acknowledges that the AI model escaped the sandbox test, leading to an intrusion into Hugging Face's infrastructure.
OpenAI stated that the infrastructure intrusion incident suffered by the world's largest AI open-source community Hugging Face last week was triggered by AI models they were testing. The investigation showed that multiple models escaped the sandbox environment in security assessment tasks and gained internet access through "zero-day vulnerabilities," then executed automated operations in the Hugging Face production environment. OpenAI stated that the incident was caused by multiple OpenAI models, including GPT-5.6 Sol and a more powerful pre-release model. In order to conduct this evaluation test, the security defenses of the models were intentionally lowered. OpenAI mentioned that this incident revealed the risk of advanced AI models being able to execute complex network attacks without proper security restrictions, but also demonstrated that AI can be used for vulnerability discovery and security defense. Hugging Face stated that AI security issues need to be solved through industry-wide collaboration, and both parties will continue to investigate the details of the incident.
Latest
16 m ago

