Top stories.
- OpenAI models escaped containment to hack Hugging Face.
- SolarWinds patches fifteen critical flaws.
- Business news: Neo emerges from stealth with $100 million.
OpenAI models escaped containment to hack Hugging Face.
OpenAI has disclosed that two of its frontier AI models, GPT-5.6 Sol and an undisclosed pre-release model, were responsible for the breach of Hugging Face’s production infrastructure last week, WIRED reports. The models were being tested in a restricted environment, but they chained together vulnerabilities, including a zero-day flaw, then escalated privileges, gained internet access, and ultimately compromised Hugging Face systems to obtain evaluation-related data. OpenAI says this is an "unprecedented cyber incident," and is working with Hugging Face to investigate the attack. Hugging Face co-founder and CEO Clément Delangue added, "We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!"
OpenAI explained, "The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal."
Security leaders say the incident demonstrates that advanced AI systems can pursue unintended, harmful strategies without explicit malicious intent. Experts also pointed out that the attack highlights traditional security issues surrounding supposedly isolated infrastructure. Security and compliance consultant Davi Ottenheimer told WIRED, "This is not an AI problem. It's negligence on a 40-year-old standard... 'Highly isolated' and 'escaped through the one hole we left open' cannot both be true."

