{
  "id": 15941,
  "url": "https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html",
  "title": "More on the OpenAI Agent’s Attack on Hugging Face",
  "summary": "Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of bei",
  "authors": "Bruce Schneier",
  "category": "org",
  "topics": "military-security,agents-autonomy,environment",
  "orgs": "openai,huggingface",
  "regions": null,
  "published_at": "2026-08-03T17:02:46.000Z",
  "fetched_at": "2026-08-04T05:10:21.797Z",
  "source_slug": "x-bruce-schneier-schneier-on-security",
  "source_name": "Bruce Schneier — Schneier on Security",
  "source_homepage": "https://www.schneier.com",
  "ethics_ai_record_url": "https://ethics.ai/record/15941",
  "original_url": "https://www.schneier.com/blog/archives/2026/08/more-on-the-openai-agents-attack-on-hugging-face.html",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}