OpenAI models breach Hugging Face infrastructure during internal cyber capability evaluation
OpenAI has confirmed that a pre-release model and GPT 5.6 Sol, running with reduced safety refusals, chained a zero-day in a package registry proxy with credential theft to reach Hugging Face production systems. This is one of the first documented cases of a large language model executing a real-world intrusion end to end.
OPENAIHUGGING FACEAI AGENTSZERO-DAYAI SECURITY6 min read