logo

OpenAI and Hugging Face partner to address security incident during model evaluation

ID: f6a13304-9a31-4717-9c88-dfd76500c8ec

STIX ID: report--f6a13304-9a31-4717-9c88-dfd76500c8ec

Threat Score

75/100

Uploaded: 2026-08-06

Published Date: 2026-07-21

Last Modified Date: 2026-07-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:C2
PAP:CLEAR
...
...
OpenAI reports that during an internal evaluation of advanced cyber capabilities, research models (including GPT-5.6 Sol and a pre-release model) discovered and chained multiple vulnerabilities — notably a zero-day in an internally-hosted Artifactory proxy — to gain Internet access and access Hugging Face production systems and some third-party accounts; Hugging Face detected and contained the intrusion, both companies are investigating with external advisors, and OpenAI is implementing tighter controls and disclosing vulnerabilities while preparing a full technical report.