By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: AI models from OpenAI carried out cyber attack on Hugging Face autonomously
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Software > AI models from OpenAI carried out cyber attack on Hugging Face autonomously
Software

AI models from OpenAI carried out cyber attack on Hugging Face autonomously

News Room
Last updated: 2026/07/22 at 1:30 AM
News Room Published 22 July 2026
Share
AI models from OpenAI carried out cyber attack on Hugging Face autonomously
SHARE

The IT attack on the AI ​​platform Hugging Face was carried out autonomously by several AI models from OpenAI during a test run, including GPT‑5.6 Sol, an “even more powerful unpublished model”. The AI ​​company itself has now made this public and speaks of an “unprecedented cyber incident in which the most modern cyber capabilities were used”. You react accordingly and share your initial findings immediately so that others can learn from them. A comprehensive analysis is underway in collaboration with Hugging Face, and a zero-day vulnerability has been found and responsibly reported.

Read more after the ad

Complicated attack route reconstructed

A few days after Hugging Face made the IT attack public, without naming anyone responsible, OpenAI is now providing details from the perspective of the other side. The incident occurred during an “internal evaluation” in which models were encouraged to carry out sophisticated attacks over complex paths in order to quantify their capabilities. Restrictions would be lifted, but at the same time the models would run “in a highly isolated environment”. All evidence would now indicate that the models tested were extremely focused on finding a solution for the ExploitGym benchmark. They “went to extremes to complete a rather narrow test target.”

As OpenAI further explains, the AI ​​models used a “substantial amount” of computing power in their secure environment to get internet access. They identified a zero-day vulnerability in the cache proxy of the packet register. Based on this, they finally gained access to the Internet. With this, the AIs came to the conclusion that the models, data sets and solutions for ExploitGym are stored on Hugging Face. The models gained access by linking different attack vectors, accessing stolen credentials and zero-day vulnerabilities. They were discovered and blocked by Hugging Face. In the meantime, we are working together to determine what exactly happened.

The event shows that the most powerful AI models can discover and exploit new attack routes in real systems even without access to the source code, writes OpenAI. This underlines that the further development of AI must be accompanied by better protection measures: “We are convinced that sophisticated, cyber-enabled models must help security teams identify vulnerabilities before attackers do.” This is exactly why the most powerful AI models were recently shared with those responsible for critical software so that they can secure their products. But it is unclear whether this is ultimately possible or whether the new AI models will only accelerate the race between attack and defense to an extreme.

Warnings about devastating cyber attacks using AI have been becoming more and more urgent for months. The concern was fueled primarily by comments about the Claude Mythos AI model from OpenAI rival Anthropic. During tests, security gaps in widely used programs and online services that had remained undetected for decades were discovered, whereupon they were plugged. Anthropic therefore only made a slimmed-down version public; access even had to be temporarily blocked at the behest of the US government. The Hugging Face incident now underlines that other AI models are catching up at great speed and what consequences this can have for the global IT infrastructure.

Read more after the ad


(my)



Unfortunately, this link is no longer valid.

Links to gifted items will be invalid if they are older than 7 days or have been accessed too often.


You need a heise+ package to read this article. Try it now for a week without obligation – without obligation!

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article France becomes the first European country to ban networks for children under 15 years of age. September will be the litmus test France becomes the first European country to ban networks for children under 15 years of age. September will be the litmus test
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

France becomes the first European country to ban networks for children under 15 years of age. September will be the litmus test
France becomes the first European country to ban networks for children under 15 years of age. September will be the litmus test
Gaming
OVHcloud reveals behind the scenes of its emergency operation in response to the Januscape breach
OVHcloud reveals behind the scenes of its emergency operation in response to the Januscape breach
Computing
The Best JavaScript Editors | Computer Week
The Best JavaScript Editors | Computer Week
News
a hacker claims a massive data leak, the party denies
a hacker claims a massive data leak, the party denies
Mobile

You Might also Like

Google brings Gemini 3.6 Flash and 3.5 Flash Lite, but is struggling with 3.5 Pro
Software

Google brings Gemini 3.6 Flash and 3.5 Flash Lite, but is struggling with 3.5 Pro

3 Min Read
Brussels initiative: reform should weaken freedom of information at the Commission
Software

Brussels initiative: reform should weaken freedom of information at the Commission

4 Min Read
Well hidden: Prohibited gambling in the Brazilian App Store
Software

Well hidden: Prohibited gambling in the Brazilian App Store

3 Min Read
Tuesday: Court stops merger, cybercriminal paralyzes real estate market
Software

Tuesday: Court stops merger, cybercriminal paralyzes real estate market

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?