Company · updated daily
Hugging Face
Hugging Face hosts the largest open-model community and originated the model-card documentation standard now used industry-wide; its safety and licensing debates are tracked here daily.
OpenAIs KI-Agent knackte nicht nur Hugging Face – was genau passierte
OpenAI-Modelle attackierten vergangene Woche scheinbar weitere Software. Die Firma erklärt nun ausführlicher, was genau passiert ist.
OpenAI's Rogue Model Claims More Victims Beyond Hugging Face
OpenAI revealed rogue AI models compromised more services than initially disclosed, including a Modal customer environment and others.
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
Dark Reading walks through the many twists and turns in the bizarre story of how OpenAI's agent AI system broke out of its sandbox and decided to target Hugging Face, and what CISOs should be aware of.
Hugging Face Hack Lessons for Cyber Defenders
Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.
OpenAI says rogue agent behind Hugging Face hack broke into additional services
The four additional targeted organizations weren’t named. OpenAI said they were not affected as severely as Hugging Face.
Measuring the Tendency of AI Agents to Go Rogue
This essay was written with Barath Raghavan, and originally appeared in The Guardian . In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of temporary server environments. It looked like the work of a sophisticated crimina
Rogue OpenAI agent compromised second tech firm's customer
An OpenAI agent compromised a customer of another technology company, the New York-based firm Modal Labs announced Wednesday. In a technical timeline posted Tuesday, the tech startup Hugging Face explained how an OpenAI agent escaped the AI firm's isolated testing sandbox and accessed another testing environment "hosted by a user of a third-party infrastructure provider."...
Rogue OpenAI agent that hacked startup tried to attack other firms
ChatGPT developer says activity by autonomous tool was not at severity or scale of what occurred at Hugging Face OpenAI has revealed that a cyber-attack carried out by a rogue AI agent had more than one victim. The ChatGPT developer said the agent – an autonomous tool able to carry out sequences of commands without human help – had located and used logins to access four other unnamed “publicly-available services” in addition to the US startup Hugging Face. Continue reading...
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversight on frontier AI systems. In an update to a blog […]
OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems
The Hugging Face breach shows there is a gap in federal policy. The frameworks to govern autonomous AI already exist—there just needs to be the desire to apply them. The post OpenAI’s rogue AI agent shows why we need federal rules for autonomous systems appeared first on CyberScoop .
‘Agents find a way’ as AI attacks evolve
A second company is drawn into the rogue AI attack on Hugging Face, with Modal clarifying its cloud platform was used as a launchpad, not breached.
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
In a new disclosure, OpenAI says its agent used exposed logins to gain access to at least four “publicly available services” in its unhinged quest to solve a test.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident Hugging Face just released this extremely detailed technical description of OpenAI's recent accidental cyberattack against their infrastructure . This attack was very sophisticated, and the resulting document doubles as a crash-course in modern adversarial security approaches. We're still waiting for more details from OpenAI on how their agent broke out of its sandbox. The package proxy that it found a zero
How A.I.’s Latest Science Fiction Scenario Came True
This week, a rogue A.I. agent acted autonomously and conducted a cyberattack on the company Hugging Face. In the latest episode of “Hard Fork,” the hosts, Kevin Roose and Casey Newtown, discuss how the attack happened and why it matters.
Helen Toner: the Hugging Face hack was just a matter of time and exposes a huge blind spot in AI policy
Over the last decade, including a stint on OpenAI’s board, I saw the open secret among AI developers: this kind of hack wasn’t just possible, but expected.
How do we prevent AI agents from going rogue? It starts with a new kind of measurement | Bruce Schneier and Barath Raghavan
Like genies of folklore, AI agents take their instructions literally – to potentially disastrous effect. We must track their ability to do what we actually mean In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked. A malicious dataset had been used to run code on one of its servers. Whoever was behind it captured internal security credentials and moved through systems over a weekend, running thousands of actions from a swarm of tempora
Hugging Face is being used to easily undress women and children
Hugging Face is being used to make nonconsensual deepfakes, and the popular open-source AI model repository is doing very little to prevent it. That's according to a new report published by the European nonprofit AI Forensics, which found that seven out of the top nine image editing models hosted by Hugging Face readily complied with […]
Nach KI-Cyberangriff: Hugging Face stellt 100-Millionen-Dollar-Forderung an OpenAI
Der KI-Cyberangriff von OpenAI hat Folgen: Der Hugging-Face-CEO fordert nun radikale Transparenz sowie eine Investition in die Absicherung seiner Plattform. ( KI , Cyberwar )
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how people use the software.
OpenAI’s Hugging Face breach has reignited the debate over alignment and control
OpenAI's Hugging Face breach has reignited debate over AI alignment and control, exposing competing views on whether increasingly capable AI should be better aligned, better contained, or both.
☕️ OpenAI aurait mis une semaine à s’apercevoir que son agent avait attaqué Hugging Face
Le 21 juillet, OpenAI a publié un communiqué étonnant : un de ses systèmes IA était responsable de l’attaque orchestrée contre Hugging Face. Des détails étaient fournis, mais l’histoire gardait des zones d’ombre. Si l’incident a été transformé en opportunité commerciale, il semble le résultat d’une vaste carence en sécurité. Dans notre article du 22 juillet, […]
C’est parti : les poids de Kimi K3, plus gros modèle IA ouvert au monde, sont en ligne
Après des semaines de bruit autour de ses benchmarks et de ses ambitions agentiques, Moonshot AI a mis en ligne ce lundi les poids complets de Kimi K3 sur Hugging Face, ouvrant la voie à un déploiement et une adaptation par n'importe quel développeur.
Boss of startup hacked by rogue OpenAI agent urges ‘radical transparency’ in investigation
Artificial intelligence firm should provide $100m for cyber defences, says Hugging Face CEO The boss of the startup hacked by an OpenAI agent has called for the investigation into the incident to show “radical transparency”. Clément Delangue, the chief executive of Hugging Face, said the “unprecedented” attack on his business required a similar response. Continue reading...
Nvidia, Palantir, Hugging Face join 34 others in race to defend open-weight AI from cyber threats
The current maelstrom of discussion surrounding the use of open-source software and open-weight AI models appears to be splitting opinion The post Nvidia, Palantir, Hugging Face join 34 others in race to defend open-weight AI from cyber threats appeared first on The New Stack .
Les IA d’OpenAI qui dérapent, une faille Linux trouvée par Claude et un million de VM patchées d’urgence chez OVHcloud : on vous raconte la semaine Cyberguerre
Trois actualités à retenir cette semaine dans le cyberespace : des agents d'OpenAI qui ont piraté Hugging Face en toute autonomie, une faille noyau critique débusquée par Claude Mythos, et le récit d'une course contre la montre chez OVHcloud pour colmater une vulnérabilité vieille de 16 ans.
James Cameron tried to warn us: ‘Skynet Day’ is now shorthand for OpenAI’s agent going rogue and hacking into a startup
In what OpenAI said was the first-ever incident of its kind, an advanced AI model escaped its “sandbox” to the internet and used stolen credentials to break into the servers of Hugging Face.
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack
"The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!"
How the OpenAI-Hugging Face Hack May Affect the Geopolitics of AI Governance
The OpenAI models that hacked Hugging Face weren’t just following instructions
And what the incident can’t tell us about alignment
New reports reveal the extent of OpenAI's loss of control during the autonomous hack on Hugging Face
In a cybersecurity test, OpenAI's most advanced models breached the boundaries of their isolated test environment, reached the open internet, and hacked the AI platform Hugging Face on their own. The attack took hours, not the weeks a human hacker would need. At least seven days passed before OpenAI realized what had happened. By then, the FBI was already involved. Earlier warning signs had apparently gone ignored. The article New reports reveal the extent of OpenAI's loss of control during the
OpenAI's rogue agent went on a hacking spree that lasted days, Reuters says
Reuters reports that the OpenAI agent that hacked Hugging Face had been free for a week before the company noticed.
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
What really happened in the Hugging Face breach
According to OpenAI, the Hugging Face security breach was an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Critics may disagree. Back The post What really happened in the Hugging Face breach appeared first on The New Stack .
Who should be responsible for OpenAI’s hack of Hugging Face?
Following OpenAI’s models hacking Hugging Face, Gabriel Weil of the University of Houston Law Center argues that AI companies need strict liability rules
DeepSeek’s boss made the case for export controls
Transformer Weekly: Trahan and Obernolte bill, OpenAI-Hugging Face hack, and CAISI chief resigns
‘AI communism’, rogue models, and the why Kimi K3 spooked Wall Street
Chinese AI lab Moonshot’s open model Kimi went viral this week for reasons that had less to do with the model itself and more to do with how the U.S. AI industry reacted to it. Meanwhile, an unreleased OpenAI model wandered outside its test environment and ended up connected to a real security breach at Hugging Face — a reminder […]
The five-day gap: what the OpenAI–Hugging Face incident should tell law firms
By Neil Cameron, Lead Analyst, Legal IT Insider The relevant unit of governance is not the model. It is the whole system through which it can act. For five days […] The post The five-day gap: what the OpenAI–Hugging Face incident should tell law firms appeared first on Legal IT Insider .
OpenAI’s breach of Hugging Face stokes fears about what’s next for AI
Washington and the technology industry are on high alert this week after OpenAI revealed that some of its AI agents went rogue and hacked into the systems of technology startup Hugging Face. The incident bore out years of warnings from the tech and cybersecurity community about the growing capabilities and hypothetical risks artificial intelligence could...
The first known runaway AI agent - or a very bad marketing stunt?
The first known runaway AI agent - or a very bad marketing stunt? Martin Alderson's commentary on the OpenAI accidental cyberattack against Hugging Face includes a couple of details I hadn't considered. First, Hugging Face offers a truly rich target if you're trying to find potential vulnerabilities that require executing arbitrary code: Hugging Face has an enormous attack surface. They have more interfaces than I can count which run untrusted models and code. While they definitely have invested
OpenAI's Hugging Face hack triggers 'AI Kill Switch' bill in Congress
OpenAI disclosed this week that some of its AI models went rogue and hacked into open-source developer platform Hugging Face.