Beyond the Breaking News

OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery

Computing News

OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery
Chinese AIOpenai

GPT-5.6 Sol and an unreleased OpenAI model exploited zero-day vulnerabilities to escape a testing sandbox and access Hugging Face’s production infrastructure

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet.

This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking. The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident. The models found a real escape route The incident began during an internal evaluation designed to measure advanced offensive cybersecurity capabilities.

OpenAI deliberately ran the models with reduced cyber refusals and without the production classifiers that ordinarily prevent them from pursuing dangerous attacks. The testing environment was heavily isolated.

However, it could reach an internally hosted proxy used to retrieve software packages. These models then spent substantial computing resources searching for an escape route and discovered a previously unknown vulnerability in that proxy, which they exploited. This allowed them to escalate their privileges and move across OpenAI’s research infrastructure, eventually reaching a system with unrestricted internet access.

Recommended Videos The models then inferred that Hugging Face might host material related to ExploitGym, the cybersecurity benchmark they were trying to complete. According to OpenAI, they used stolen credentials and additional zero-day vulnerabilities to find a remote-code-execution path into Hugging Face’s servers and retrieve test solutions from a production database. OpenAI detected unusual activity internally, while Hugging Face’s security systems identified and stopped the intrusion on its infrastructure.

Hugging Face stated that the incident exposed a limited collection of internal datasets and service credentials. It has found no evidence that public models, datasets, or container images were altered. But its assessment of possible customer or partner impact is still ongoing. A Chinese AI helped investigators sort through this mess Hugging Face faced a strange problem while examining more than 17,000 recorded events from the attack.

Its investigators initially tried using frontier AI models available through commercial APIs. However, their safety systems managed to block malicious commands, exploit payloads, and command-and-control artifacts contained in the evidence. The hosted models could not reliably distinguish forensic work from someone requesting help with an attack. The company switched to GLM 5.2, an open-weight model developed by China’s Z.ai, and ran it locally.

AI-driven forensic agents used the model to reconstruct the timeline, identify compromised credentials, extract indicators of compromise, and even managed to separate genuine activity from decoys. Hugging Face says the process took hours instead of the days a conventional investigation might have required. Keeping GLM on its own infrastructure also prevented credentials and attack data from leaving its environment. Hugging Face’s security teams later removed the footholds and rebuilt the compromised system.

So the GLM didn’t single-handedly contain the intrusion. OpenAI built AI capable of pulling off this kind of intrusion, while Hugging Face’s experience suggests defenders may need equally capable models waiting on the other side.

GooglePlease follow us on Google to support us
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

DigitalTrends /  🏆 95. in US

Chinese AI Openai

 

United States Latest News, United States Headlines

Similar News: You can also read news stories similar to this one that we have collected from other news sources.

OpenAI Appears to Be Missing Its Sales Goals by a Vast MarginOpenAI Appears to Be Missing Its Sales Goals by a Vast MarginThe company behind ChatGPT is on track to undershoot its five-year revenue projection by upward of 90 percent.
Read more »

Author Invited to Give Speech at OpenAI Headquarters, Uses Opportunity to Trash AI to Their FacesAuthor Invited to Give Speech at OpenAI Headquarters, Uses Opportunity to Trash AI to Their FacesOpenAI invited prominent author Dave Eggers to talk to its workers — and he relished the opportunity to set the record straight.
Read more »

OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another companyOpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another companyThe intrusion involved OpenAI’s GPT‑5.6 Sol and another model still in testing.
Read more »

Hugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now SaysHugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now SaysIt was reportedly an evaluation that went haywire involving GPT-5.6 Sol, along with another even more advanced OpenAI model.
Read more »



Render Time: 2026-08-08 04:18:12