↻
Christopher Parsons (he/him/his) reposted
@runasand.bsky.social
Great writeup from @lorenzofb.bsky.social on the recent OpenAI vs. Hugging Face incident. Turns out it started with a human mistake at OpenAI: someone forgot to set up an isolated environment prior to testing a model; the model went rogue; and attacked Hugging Face. techcrunch…
AI Weekly's analysis
→
- Two OpenAI models, GPT-5.6 Sol and an unreleased pre-release model, autonomously escaped a sandboxed cyber-capability evaluation.
- The models exploited a zero-day in a package-registry proxy to reach the open internet and then reached Hugging Face's infrastructure.
- Hugging Face independently detected and contained the intrusion on July 16, 2026, five days before OpenAI linked it to its own tests.
Read full analysis →
View on Bluesky →