{"id":14724,"date":"2026-08-04T12:02:07","date_gmt":"2026-08-04T12:02:07","guid":{"rendered":"https:\/\/news.theck1.no\/?p=14724"},"modified":"2026-08-04T12:02:07","modified_gmt":"2026-08-04T12:02:07","slug":"openai-agent-breaks-free-and-hacks-hugging-face-2","status":"publish","type":"post","link":"https:\/\/news.theck1.no\/?p=14724","title":{"rendered":"OpenAI Agent Breaks Free and Hacks Hugging Face"},"content":{"rendered":"<div style=\"margin-bottom:1em; color:#666; font-size:0.9em;\">\n<strong>SingularityHub &#8211; Hussein Abbass<\/strong><br \/>\n &bull;<br \/>\nJuly 23, 2026\n<\/div>\n<hr\/>\n<div class=\"wp-block-post-excerpt\">\n<p class=\"wp-block-post-excerpt__excerpt\">The incident is a first and signals a seismic shift in cybersecurity. <\/p>\n<\/div>\n<p>An autonomous agent powered by OpenAI\u2019s advanced <a target=\"_blank\" href=\"https:\/\/singularityhub.com\/tag\/artificial-intelligence\/\">artificial intelligence<\/a> models went rogue during a security test and hacked multi-billion dollar tech startup, <a target=\"_blank\" href=\"https:\/\/singularityhub.com\/2025\/12\/15\/hugging-face-says-ai-models-with-reasoning-use-100x-more-energy-than-those-without\/\">Hugging Face<\/a>, last week.<\/p>\n<p>The agent didn\u2019t just exploit vulnerabilities in Hugging Face\u2019s systems to achieve what it perceived as a strategic gain. It also exploited vulnerabilities within OpenAI\u2019s infrastructure.<\/p>\n<p>Of course, hacks are very common cyber threats that organizations face frequently. But this incident is different, because the AI agent acted without any human input. It signals a <a target=\"_blank\" href=\"https:\/\/singularityhub.com\/2026\/04\/10\/anthropics-mythos-ai-uncovered-serious-security-holes-in-every-major-os-and-browser\/\">seismic shift in cybersecurity<\/a>, and shows that governments and tech companies need to take urgent action to prevent this risk escalating.<\/p>\n<p>Even OpenAI described the attack as \u201cunprecedented\u201d and <a target=\"_blank\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\">acknowledged it expects<\/a> similar ones \u201cto become more commonplace with the proliferation of increasingly cyber-capable models.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-a-company-under-attack\">A Company Under Attack<\/h2>\n<p>Hugging Face is famous in the AI space. Its mission is to \u201c<a target=\"_blank\" href=\"https:\/\/huggingface.co\/huggingface\">democratize good machine learning<\/a>\u201d by providing benchmark datasets, community collaboration tools, and robotic platforms. The company is <a target=\"_blank\" href=\"https:\/\/www.reuters.com\/technology\/ai-startup-hugging-face-valued-45-bln-latest-round-funding-2023-08-24\/\">valued at $4.5 billion<\/a>.<\/p>\n<p>On July 16, the company <a target=\"_blank\" href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\">announced<\/a> it had been attacked, with a hacker obtaining unauthorized access to some internal datasets and credentials. It said the hacker was likely \u201can autonomous AI agent system\u201d due to the sophistication of the attack.<\/p>\n<p>Five days later, OpenAI <a target=\"_blank\" href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\">announced<\/a> the attack had been driven by some of its models: <a target=\"_blank\" href=\"https:\/\/openai.com\/index\/previewing-gpt-5-6-sol\/\">GPT-5.6 Sol<\/a> and a yet-to-be released model.<\/p>\n<p>The tech giant was conducting what are known as \u201c<a target=\"_blank\" href=\"https:\/\/link.springer.com\/book\/10.1007\/978-3-319-08281-3\">red teaming<\/a>\u201d exercises. These are essentially simulated cyber attacks that help identify the capabilities, risks, and vulnerabilities of AI systems before they are publicly released. They are typically conducted within an isolated environment to ensure potentially dangerous systems do not escape and cause harm to real systems.<\/p>\n<p>But in this case, the AI agent did escape\u2014even though OpenAI had some guardrails in place to prevent this.<\/p>\n<p>Hugging Face became a lucrative opportunity for the AI agent. It hosts ExploitGym, a benchmark that tests an AI agent\u2019s ability to exploit real-world systems. The AI decided to turn every stone upside down to obtain access. With persistence, it succeeded.<\/p>\n<p>Hugging Face was confronted with a challenge when attempting to use external AI services to diagnose the problem. The guardrails around more advanced models such as GPT-5.6 Sol and Claude Fable 5 are intended to stop them being used for cyber attacks\u2014but they can also stop the models being used for sophisticated cyber defense.<\/p>\n<p>So Hugging Face resorted to using an open-source model, GLM 5.2, developed by the Chinese company Z.AI, to <a target=\"_blank\" href=\"https:\/\/siliconangle.com\/2026\/07\/20\/hugging-face-uses-open-weights-z-ai-glm-5-2-defend-attacker-commercial-frontier-model-refusal\/\">counter the cyber attack<\/a>.<\/p>\n<p>Hugging Face said GLM 5.2 was an advantage because it was not exposed to the attack data. Both Hugging Face and OpenAI are collaborating on forensic analysis, post-incident recovery, and risk mitigation strategies.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-more-sophisticated-threats-are-coming\">More Sophisticated Threats Are Coming<\/h2>\n<p>A March 2025 <a target=\"_blank\" href=\"https:\/\/arxiv.org\/abs\/2603.11214\">study<\/a> by the United Kingdom\u2019s AI Security Institute showed the best AI could complete 80 percent of the steps needed to gain full control of a portion of an external system. Within four months, it reached 100 percent.<\/p>\n<p>Z.AI\u2019s GLM 5.2 was only released in June, with 744 billion internal variables, known in the world of AI as \u201cparameters.\u201d The fact that Hugging Face assessed, vetted, and deployed it within four weeks should be an eye-opener for organizations with long acquisition cycles.<\/p>\n<p>The connectivity we all enjoy today can equally be our greatest threat. Cyber threats spread faster than human viruses and can create <a target=\"_blank\" href=\"https:\/\/cybersecurityventures.com\/official-cybercrime-report-2025\/\">economic damage similar in magnitude to a country\u2019s GDP<\/a>.<\/p>\n<p>More sophisticated cyber threats\u2014the kind exemplified by the Hugging Face hack\u2014will exploit the security layers that humans designed for human attackers, regardless of how sophisticated our designs are.<\/p>\n<p>Indeed, in this particular case, even OpenAI\u2019s own understanding of its models couldn\u2019t predict or contain the rogue AI agent. This shows the need for all AI companies to urgently update and strengthen their guardrails, in order to help prevent a similar attack occurring with far more devastating consequences.<\/p>\n<p>It is good to see Hugging Face and OpenAI collaborating on the investigation into the attack. This showcases the importance of putting aside market competition and blame when the situation demands.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-an-early-warning\">An Early Warning<\/h2>\n<p>The fact that Hugging Face used Z.AI\u2019s open-source model to diagnose and counter the attack also shows the advantages of not relying on just a few pieces of tech.<\/p>\n<p>States that are not in the game of developing their own AI models need to learn from this incident the value of being different. It is not too late to design new models that could save us in situations when the most advanced models fail\u2014or, even worse, attack us.<\/p>\n<p>Indeed, last week, another Chinese company, Moonshot AI, released Kimi K3. This model has 2.8 trillion parameters, its advanced performance <a target=\"_blank\" href=\"https:\/\/www.smh.com.au\/technology\/moon-landing-why-this-chinese-ai-model-rattled-global-sharemarkets-20260720-p60gr1.html\">stunning<\/a> the tech world.<\/p>\n<p>It is no longer a question of \u201cif\u201d <a target=\"_blank\" href=\"https:\/\/singularityhub.com\/2025\/01\/04\/what-is-an-ai-agent-a-computer-scientist-explains-the-next-wave-of-ai-tools\/\">AI agents<\/a> go rogue and attack us by themselves. The Hugging Face incident is an early warning that we must accelerate our preparedness. The threat is real and here.<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/counter.theconversation.com\/content\/288106\/count.gif?distributor=republish-lightbox-advanced\" alt=\"The Conversation\" width=\"1\" height=\"1\" style=\"border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important\" referrerpolicy=\"no-referrer-when-downgrade\">\n<\/p>\n<p><em>This article is republished from <a target=\"_blank\" href=\"https:\/\/theconversation.com\">The Conversation<\/a> under a Creative Commons license. Read the <a target=\"_blank\" href=\"https:\/\/theconversation.com\/openais-models-autonomously-hacked-a-tech-startup-it-signals-a-seismic-shift-in-cybersecurity-288106\">original article<\/a>.<\/em><\/p>\n<p>The post <a href=\"https:\/\/singularityhub.com\/2026\/07\/23\/openai-agent-breaks-free-and-hacks-hugging-face\/\">OpenAI Agent Breaks Free and Hacks Hugging Face<\/a> appeared first on <a href=\"https:\/\/singularityhub.com\">SingularityHub<\/a>.<\/p>\n<p style=\"margin-top:1.5em;\"><a href=\"https:\/\/singularityhub.com\/2026\/07\/23\/openai-agent-breaks-free-and-hacks-hugging-face\/\" target=\"_blank\" rel=\"noopener\">Read the full article &rarr;<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SingularityHub &#8211; Hussein Abbass &bull; July 23, 2026 The incident is a first and signals a seismic shift in cybersecurity. An autonomous agent powered by OpenAI\u2019s advanced artificial intelligence models went rogue during a security test and hacked multi-billion dollar tech startup, Hugging Face, last week. The agent didn\u2019t just exploit vulnerabilities in Hugging Face\u2019s<\/p>\n<p class=\"more-link\"><a href=\"https:\/\/news.theck1.no\/?p=14724\" class=\"themebutton2\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-14724","post","type-post","status-publish","format-standard","hentry","category-positive-news"],"_links":{"self":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/14724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14724"}],"version-history":[{"count":0,"href":"https:\/\/news.theck1.no\/index.php?rest_route=\/wp\/v2\/posts\/14724\/revisions"}],"wp:attachment":[{"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.theck1.no\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}