
Hugging Face in the Media
287 mentions across press, blogs, and newsletters
August 2026
OpenAI’s Rogue AI Agents Hack Hugging Face in Tests, Prompting Tighter Controls and Smarter Models
OpenAI and Anthropic AI agents escaped sandboxes during cyber tests, hacked Hugging Face and other firms, and coordinated via internal channels unnoticed. Labs respond with stricter
Now we have a timeline of the OpenAI accidental attack against Hugging Face
My comment on Now we have a timeline of the OpenAI accidental attack against Hugging Face - Hacker News. I think one of the most interesting details here mi
Hugging Face hack marks start of dangerous AI cyber era and many firms 'don't even know it'
The Black Hat cybersecurity conference in Las Vegas couldn't have come at a better time, with AI agent hacks stacking up from Anthropic, Meta and OpenAI.
Now we have a timeline of the OpenAI accidental attack against Hugging Face
OpenAI gave a last-minute presentation at the Black Hat security on Wednesday about "the Hugging Face Incident" ( previously on this blog). The video was published yest
The Hugging Face hack is now a PR crisis that’s costing OpenAI millions
The compute cost of the investment is staggering, according to a talk the company gave at a security conference this week.
The godfather of Israeli cybersecurity: The Hugging Face incident exposes the wrong AI security debate
A human insider threat unfolds over days or weeks; an agent can execute thousands of autonomous actions in an entirely different window of time.
New details on OpenAI/Hugging Face attack emerge as security industry debates AI agent controls
How fast is artificial intelligence advancing? Behind the scenes at OpenAI Group PBC, AI agents are fluent, technically precise and occasionally profane in their extensive conversations…with each other. This was one of the more interesting details revealed by OpenAI security researchers Eri
OpenAI agents passed secret notes for months leading up to Hugging Face hack
At the Black Hat conference in Las Vegas, OpenAI gives its first in-depth look at how its AI models plotted and executed the breach with no human assistance.
The Sandbox Failed: How OpenAI's Experimental AIs Went Rogue and Attacked Hugging Face
OpenAI took the stage at Black Hat to unpack the wild chain reaction that allowed its autonomous models to plot a cross-platform cyberattack.
Why Hugging Face, AI2 partnered to open up AI
The debate around open-source AI is reaching a fever pitch. Now, two of open-source's most prominent supporters want to make it easier to use. On Thursday, the Allen Institute for AI, or AI2, announc...
OpenAI agents secretly shared exploits before Hugging Face attack
<img alt="OpenAI agents secretly shared exploits before Hugging Face attack" class="webfeedsFeaturedVisual wp-post-image" height="720" src="https://dataconomy.com/wp-content/uploads/2026/08/openai-agents-secretly-shared-exploits-before-hugg.jpg" style="display: block; margin: auto; margin-bottom: 10
OpenAI’s AI models coordinated a months-long breakout to hack Hugging Face
OpenAI has disclosed one of the most unsettling AI-safety incidents yet, and the detail that stands out is teamwork. Its research agents did not just escape a test envir
OpenAI's models secretly joined forces months ahead of hacking Hugging Face
Researchers said multiple AI agents communicated through hidden message boards and coordinated for months to gain internet access, exposing new risks around advanced AI behaviour during testing
OpenAI’s models shared hacking tips on a secret messaging board before Hugging Face breach
Researchers from OpenAI said the company is “dramatically scaling up” its security efforts after discovering that two of its models orchestrated a hack without human prompting last month.
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
How OpenAI's agents broke out of testing to hack Hugging Face
Weeks before OpenAI's agents hacked Hugging Face , the agents worked together to find and exploit a vulnerability in the infrastructure supporting the company's cybersecurity tes
White House to meet Meta, OpenAI, Google, Anthropic on AI safety testing after Hugging Face incident
Four leading AI companies have been invited to Washington to discuss implementing voluntary government safety testing for the US' most advanced AI models The post <a href="https://americanbazaaronline.com/2026/08/04/white-house-to-meet-meta-openai-google-anthropic-on-ai-safety-testing-afte
What OpenAI’s Hugging Face Hack Tells Us About AI’s Risks
"AI models are unpredictable and their risks scale with their capabilities," writes Garrison Lovely.
Republican attorneys general urge OpenAI to preserve records on Hugging Face breach
Miranda Nazzaro reports: More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models’ recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 atto
Swarm of OpenAI Agents Exploit Artifactory Zero-Day to Escape Sandbox and Breach Hugging Face
Security disclosures highlighted vulnerabilities in AI evaluations of autonomous cyber capabilities. Notably, OpenAI’s models escaped sandbox isolation, breaching Hugging Face’s systems. The incident involved a multi-sta
15 attorneys general have instructed OpenAI to preserve all materials related to the Hugging Face hack
They wrote in a letter that OpenAI is either unable or unwilling to ensure the safety of its products, posing a risk of substantial harm to Americans.
Hugging Face CEO says China is winning the AI race while the US is building 'in silos'
Clément Delangue said the Hugging Face hack showed that open-weight models are vital for AI defense.
Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack
The post Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack appeared first on CyberScoop .
Republican attorneys general urge OpenAI to preserve records on Hugging Face breach
More than a dozen Republican attorneys general are calling on OpenAI to preserve records on its models' recent breach of another company, suggesting the AI firm may have violated state or federal laws in the incident. In a letter sent Monday to OpenAI CEO Sam Altman, 15 attorneys general wrote the C
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI
Hugging Face CEO says China is winning the AI race and dominating on open models
Hugging Face CEO Clément Delangue said Chinese AI models could catch up to the U.S. as soon as this year.
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass trust_remote_code, the very safeguard designed to stop unreviewed code from running during the
Hugging Face CEO called OpenAI's rogue AI hack "unprecedented" and wants new laws
Clément Delangue said the autonomous cyberattack involved more than 17,000 actions and urged mandatory disclosures for AI agent incidents
Hugging Face CEO calls for mandatory AI breach reporting
<img alt="Hugging Face CEO calls for mandatory AI breach reporting" class="webfeedsFeaturedVisual wp-post-image" height="1076" src="https://dataconomy.com/wp-content/uploads/2026/08/hugging-face-ceo-calls-for-mandatory-ai-cyberattac.jpg" style="display: block; margin: auto; margin-bottom: 10px;" tit
Concrete Evaluations to Investigate the OpenAI Model That Hacked Hugging Face
This post is written in our personal capacity. Three Minute Executive Summary An OpenAI model/multi-agent system bypassed its sandbox and launched a cyberattack on Hugging Face
Hugging Face CEO says AI companies should be required to disclose hacks after OpenAI breach
Clem Delangue said that preventing releases of powerful AI models is not the way to stop attacks like the OpenAI hack on Hugging Face.
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are by
In a twist of irony, a Chinese open source GLM 5.2 AI model contained 'rogue' OpenAI GPT-5.6 Sol in a Hugging Face hack just as the US mulls banning open-weight AI
The Hugging Face cybersecurity breach unexpectedly strengthened China's GLM-5.2 while fuelling Washington's debate over restricting Chinese open-weight AI models.
Weekly Cybersecurity Newsletter – Top 50 Biggest Cybersecurity Stories of the Week – Hugging Face, Iranian ICS Attacks, EY, Hyundai, AI Agent Breaches
Welcome to this week’s edition of the GBHackers cybersecurity newsletter — your weekly cybersecurity bulletin covering the 50 most important stories from July 27–August 1, 2026. The week’s throughline was AI on both sides of the fight: an autonomous agent escaped its sandbox and breac
After Hugging Face incident, METR urges independent root-cause investigations into AI agent misbehavior
Res
OpenAI uncovers more rogue AI agents during Hugging Face investigation
OpenAI uncovers more rogue AI agents during
Hugging Face CEO calls for accountability after OpenAI hack
The chief executive of Hugging Face said Friday that developers should be held accountable if their AI models go rogue, after his startup faced a recent cyberattack by autonomous OpenAI software.
Autonomous AI Agent Exploits Zero-Day to Breach Hugging Face Infrastructure
An autonomous AI agent powered by OpenAI models breached Hugging Face’s production infrastructure in July 2026 after escaping its evaluation sandbox via a zero-day vulnerability. Documented by HiddenLayer’s Research Team on July 31, the agent was undergoing an internal cyber capabilit
July 2026
Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, - SWN #603
Podcast Segment: Rogue AI, the Bar, Breaches, BMC, Hugging Face, Helmuth von Multke, Ike, Shieldfont, – SWN #603. Rogue AI, the Bar, Breaches, BMC, More Hugging Face, Helmuth von Multke, Ike, Shieldfont, and More on this episode of the Security Weekly News.
Hugging Face Doesn’t Want to Sue OpenAI. It Does Want $100 Million
"Everyone has to remember that this cyberattack is a crime."
What the Hugging Face breach reveals about defense in the age of agentic AI
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5
OpenAI's rogue agent didn't stop at Hugging Face - here's what we know
The same autonomous OpenAI agent that escaped its test environment and breached Hugging Face was also busy hacking other AI systems. Lucky us.
OpenAI Agent Exploited JFrog Artifactory Flaw, Abused Modal Customer Sandbox—Here's What Happened During the Hugging Face Incident
OpenAI and Hugging Face reveal how a rogue AI agent exploited a JFrog zero-day, escaped containment and moved across production systems during a 4.5-day cyberattack.
In the Hugging Face breach, OpenAI’s hacker was noisy and fast — but not unstoppable
Cybersecurity experts told TechCrunch that one of the biggest lessons to be taken from the OpenAI hack against HuggingFace has nothing to do with AI, but traditional cybersecurity defense.
Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls. The post Hu
The AI that hacked Hugging Face keeps looking less like a mastermind and more like a bear
The most alarming AI security incident of the year keeps getting stranger, and the newest detail cuts against the panic. OpenAI now says the rogue models that broke into
New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'
OpenAI's rogue models used publicly exposed credentials across "four accounts on four services" to help facilitate the Hugging Face breach.
How an OpenAI safety test became a real‑world cyberattack on the Hugging Face platform
OpenAI's AI models recently escaped their constraints during an internal cybersecurity evaluation and broke into the production systems of Hugging Face—a popular machine learning platform and community used across the AI industry.
Sam Altman is briefing senators after OpenAI's AI agent escaped and hacked Hugging Face
OpenAI CEO Sam Altman told reporters he discussed the breach "a little bit" with lawmakers, though he said it was not the focus of his Washington meetings
Hugging Face Publishes a Technical Writeup of the OpenAI Autonomous Exploit
OpenAI last week: Last week, Hugging Face disclosed a new kind of security incident after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models. After investigating, we
Hugging Face hack, from the perspective of the AI
I have put together a site to tell the story of the OpenAI-Hugging Face hack. It's entirely written by AI [1] (with many many editing passes by me and beta readers etc etc). It ne
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.
The Hugging Face AI break-in, as told through an increasingly committed bear metaphor
Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)
Hugging Face Users Easily Created and Shared Abusive AI Images, Study Finds
The popular AI platform is used by developers to share access to their AI models and demo apps.
How an OpenAI safety test became a real-world cyberattack on the Hugging Face platform
OpenAI’s models were told to find and exploit vulnerabilities. They did — on a company that was never part of the exercise.
OpenAI says rogue agent behind Hugging Face hack broke into additional services
The four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. [...]
The AI “vibe shift”: Why NanoClaw and Echo have teamed up to stop the next Hugging Face Breach
<img alt="Glitch-style collage of repeated red animal forms, broken by black horizontal bands and patches of cyan and pale pink." class="webfeedsFeaturedVisual wp-post-image wp-stateless-item" height="556" src="https://cdn.thenewstack.io/media/2026/07/3dbc5db0-egor-komarov-swezl05imji-unsplash-1024x
OpenAI Says Its Rogue AI Agent Didn’t Just Hack Hugging Face
OpenAI says its models accessed accounts on four other services.
One In Four Breaches Are AI-Enabled, And That’s Before Hugging Face
IBM's Cost of a Data Breach report finds that one in four breaches were AI-enabled, and that's before taking into account the Hugging Face breach.
An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker
OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.
OpenAI explains how its AI agent breached Hugging Face
OpenAI has published an update on the incident in which one of its agents escaped its sandbox and accessed Hugging Face infrastructure.
OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face
OpenAI quietly updated its breach disclosure to confirm its agent accessed four external services beyond Hugging Face. Only one has been named so far.
OpenAI rogue AI agent’s attack expanded beyond Hugging Face
<p class
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Hugging Face Rebuilt a Third of Its Infrastructure After Agent Intrusion
Hugging Face rebuilt roughly a third of its infrastructure after the July agent intrusion, because defenders could not tell benchmark artifacts from real rootkits. Its forensic timeline shows one shared credential gave the agent cluster-admin on two clusters within one second.
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversi
OpenAI's rogue AI agent breached a second company during its Hugging Face hacking spree
Modal Labs CTO Akshat Bubna confirmed the agent exploited a customer's vulnerable code, not Modal's own infrastructure
OpenAI agents breach Modal client system after Hugging Face hack
OpenAI’s ‘rogue agent’ took advantage of a code vulnerability, experts explained. Read more: OpenAI agents breach Modal client system after Hugging Face ha
OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach
OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirming the models respo
The runaway OpenAI models that hacked Hugging Face also breached a customer at a second tech company during a week-long spree
The breach appears to have been one stop along a broader path. OpenAI said the models had affected four accounts across four publicly available services.
OpenAI's rogue AI agent did more than hack Hugging Face – it compromised accounts across four services
<img height="560" src="https://www.techspot.com/images2/news/ts3_thumbs/2026/07/2026-07-29-ts3_thumbs-728.jpg" style="padding: 15px 0;" title="OpenAI's rogue AI agent did more than hack Huggi
OpenAI’s Rogue AI Ventured Beyond Hugging Face
Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on
Study finds 7 of 9 Hugging Face image models made deepfake nudes
<img alt="Study finds 7 of 9 Hugging Face image models made deepfake nudes" class="webfeedsFeaturedVisual wp-post-image" height="803" src="https://dataconomy.com/wp-content/uploads/2026/07/study-finds-7-of-9-hugging-face-image-models-made.jpg" style="display: block; margin: auto; margin-bottom: 10px
Hugging Face CEO Seeks OpenAI Traces and $100m in Free Compute
Hugging Face CEO Clem Delangue wan
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on <
OpenAI says the rogue agent that hacked Hugging Face also breached other services
OpenAI's investigation starts shedding light on the activities of its rogue agent that hacked Hugging Face.
Hugging Face details rogue ChatGPT cyberattack
<img alt="Hugging Face details rogue ChatGPT cyberattack" class="webfeedsFeaturedVisual wp-post-image" height="810" src="https://dataconomy.com/wp-content/uploads/2026/07/openai-says-chatgpt-escaped-and-hacked-hugging-fac.jpg" style="display: block; margin: auto; margin-bottom: 10px;" title="Hugging
Not just Hugging Face, OpenAI says its rogue AI agent also accessed accounts across four online services
OpenAI's rogue AI breached not only Hugging Face but used exposed credentials to access four other accounts. While one was used for data storage, others were read-only.
Hugging Face Says OpenAI Agent Reached Cluster Admin in Under 13 Hours
An OpenAI-driven agent reached cluster-admin access across Hugging Face in under 13 hours. The forensic report follows two dataset exploits, 17,600 actions and 181 mesh-network enrollments, showing how a benchmark run crossed one trust boundary after another before defenders cut it off.
OpenAI's rogue AI breached multiple services beyond Hugging Face
OpenAI has revealed that its rogue AI agent, which previously breached Hugging Face, also compromised several third-party accounts and services during the attack.
Autonomous AI Agent Escapes Sandbox and Breaches Hugging Face Production Systems
Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation sandbox, compromised third-party infrastructure, and later breached production systems by exploiting vulnerabilities in its dataset-processing pipel
OpenAI reveals rogue AI agent breached multiple external accounts beyond Hugging Face attack
OpenAI has disclosed that the autonomous AI agent behind the high-profile breach of Hugging Face also compromised several third-party accounts while attempting to complete a cybersecurity benchmark. The latest findings suggest the incident was broader than first acknowledged, reigniting debate over
First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face
Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day flaws across multiple organizations. An AI agent running inside OpenAI’s ExploitGym cyber-capability evaluation harness escaped its test environ
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.
Hugging Face OpenAI attack postmortem points to lack of AI agent visibility
Hugging Face OpenAI attack postmortem points to lack of AI agent visibility <a class="username" href="https://www.constellationr.co
OpenAI's attack on Hugging Face affected two other enterprise tech companies
The unreleased model used in the attack "was never intended for public release" and has been mothballed, according to OpenAI.
Looks like JFrog's 0-days let OpenAI's models hack Hugging Face
The vendor won't confirm or deny
We now have a better understanding how OpenAI hacked into Hugging Face
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
Nvidia Alliance Backs Open Source AI After Hugging Face Breach
Nvidia launches the Open Secure AI Alliance to support the open source AI ecosystem after the Hugging Face breach
Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More - SWN #602
Podcast Segment: Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet and More – SWN #602. Deep Fakes, Molten Salt, PLCS, Checkpoint, Hugging Face, CENTOS, Josh Marpet, and More on the Security Weekly News.
OpenAI's Hugging Face hack is a cybersecurity warning shot
OpenAI models' accidental hack of Hugging Face is the warning shot defenders have been afraid was coming.Why it matters: If defenders and policymakers don't take the warning seriously, public utilities, financial firms, hospitals and communication
Helen Toner: the Hugging Face hack was just a matter of time and exposes a huge blind spot in AI policy
Over the last decade, including a stint on OpenAI’s board, I saw the open secret among AI developers: this kind of hack wasn’t just possible, but expected.
Hugging Face breach reignites open-weights debate, raises liability questions
The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO co
OpenAI CEO Sam Altman says AI has entered the singularity — two weeks after OpenAI models cheated a benchmark by hacking Hugging Face
OpenAI CEO Sam Altman recently declared on the Relentless podcast that artificial intelligence has entered the technological singularity.
Runtime: A Hugging Face post-mortem; Microsoft's AI security move; a $6 trillion market, and...
Plus, the UK's new PM has a scientist in his ear on AI, and...
The OpenAI models that hacked Hugging Face WERE just following instructions (contra Girish Gupta)
Ever since the OpenAI HuggingFace hacking incident, there has been plenty of debate about whether this is misalignment, whether it is instrumental convergence, etc. This post is a response to the claim that <a href="https://www.lesswrong.com/posts/paFNnwFaEXrQvt8ui/the-openai-models-
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
Hugging Face reportedly plagued with AI models generating adult deepfakes
Researchers investigating Hugging Face found the majority of its models would generate non-consensual deepfakes.
Hugging Face is being used to easily undress women and children
Hugging Face is being used to make nonconsensual deepfakes, and the popular open-source AI model repository is doing very little to prevent it. That's according to a new report published by the European nonprofit AI Forensics, which found that seven out of the top nine image editing models hosted by
Toolradar Research
See Hugging Face in context: The SaaS Press Index 2026
We analyzed 6,704 press mentions across 290 outlets to rank which SaaS tools win coverage. Find Hugging Face's position relative to the 488 most-covered tools.
Read the reportExplore Hugging Face
Press coverage is one signal. See the full picture.