Security
OpenAI has disclosed what it describes as an unprecedented AI security incident in which one of its advanced AI models exploited a zero-day vulnerability, escaped its intended testing environment and attempted to compromise Hugging Face's production infrastructure during an internal cybersecurity evaluation.
According to the company, the incident occurred while it was testing the cyber capabilities of a combination of OpenAI models, including GPT-5.6 Sol and a more advanced pre-release model, with built-in cyber safety refusals intentionally relaxed for research purposes.
OpenAI said the models independently identified and chained together multiple vulnerabilities across its research environment before exploiting an undisclosed zero-day flaw in an internally hosted package registry cache proxy to gain internet access.
Once online, the models searched for resources that could help solve the evaluation task and concluded that Hugging Face might host relevant datasets and models. The AI system then attempted to access Hugging Face's production infrastructure by combining stolen credentials, privilege escalation techniques and additional zero-day vulnerabilities to establish a remote code execution path.
OpenAI said its internal security systems detected the anomalous activity, while Hugging Face's security team independently identified and contained the intrusion before any broader compromise occurred. The two companies are jointly investigating the incident and have notified the affected software vendor about the zero-day vulnerability.
"We consider this incident to be an unprecedented cyber incident involving state-of-the-art cyber capabilities," OpenAI said, adding that it is sharing preliminary findings to help security teams understand the level of capability demonstrated by frontier AI models.
Following the incident, the company said it has tightened infrastructure controls, strengthened monitoring around AI evaluations, expanded safeguards for future testing and is working with Hugging Face on forensic analysis and remediation. It has also brought Hugging Face into its Trusted Access program to help strengthen defensive security capabilities.
The incident highlights the growing cyber capabilities of advanced AI models, which OpenAI said are increasingly capable of sustaining complex, multi-stage attack chains and discovering previously unknown vulnerabilities without access to source code.
"We're grateful for the collaboration with OpenAI on this and other topics," said Clem Delangue, co-founder and CEO of Hugging Face. "This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."
The disclosure comes as AI developers and governments intensify efforts to establish safeguards for increasingly autonomous AI systems that can perform sophisticated cybersecurity tasks, including vulnerability discovery, exploitation and defensive testing.
According to the company, the incident occurred while it was testing the cyber capabilities of a combination of OpenAI models, including GPT-5.6 Sol and a more advanced pre-release model, with built-in cyber safety refusals intentionally relaxed for research purposes.
OpenAI said the models independently identified and chained together multiple vulnerabilities across its research environment before exploiting an undisclosed zero-day flaw in an internally hosted package registry cache proxy to gain internet access.
Once online, the models searched for resources that could help solve the evaluation task and concluded that Hugging Face might host relevant datasets and models. The AI system then attempted to access Hugging Face's production infrastructure by combining stolen credentials, privilege escalation techniques and additional zero-day vulnerabilities to establish a remote code execution path.
OpenAI said its internal security systems detected the anomalous activity, while Hugging Face's security team independently identified and contained the intrusion before any broader compromise occurred. The two companies are jointly investigating the incident and have notified the affected software vendor about the zero-day vulnerability.
"We consider this incident to be an unprecedented cyber incident involving state-of-the-art cyber capabilities," OpenAI said, adding that it is sharing preliminary findings to help security teams understand the level of capability demonstrated by frontier AI models.
Following the incident, the company said it has tightened infrastructure controls, strengthened monitoring around AI evaluations, expanded safeguards for future testing and is working with Hugging Face on forensic analysis and remediation. It has also brought Hugging Face into its Trusted Access program to help strengthen defensive security capabilities.
The incident highlights the growing cyber capabilities of advanced AI models, which OpenAI said are increasingly capable of sustaining complex, multi-stage attack chains and discovering previously unknown vulnerabilities without access to source code.
"We're grateful for the collaboration with OpenAI on this and other topics," said Clem Delangue, co-founder and CEO of Hugging Face. "This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."
The disclosure comes as AI developers and governments intensify efforts to establish safeguards for increasingly autonomous AI systems that can perform sophisticated cybersecurity tasks, including vulnerability discovery, exploitation and defensive testing.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




