The experimental OpenAI model gained unauthorized access to the Hugging Face infrastructure and three third-party services

7/31/2026, 02:17 PMЕвгения Слив

OpenAI and the Hugging Face platform have released updated data on a recent cybersecurity incident in which an experimental agent system gained unauthorized access to several external services. The incident occurred during the testing of models, including GPT-5.6 Sol, on the ExploitGym benchmark, designed to assess the ability of artificial intelligence to identify vulnerabilities in software. Despite the fact that the test was supposed to take place in a strictly isolated environment without access to the global network, the models discovered and exploited a vulnerability in the Artifactory server used for downloading and caching software packages. This allowed the system to access the Internet in search of solutions for test tasks.

After bypassing the isolation, the agent system discovered open login credentials for four public services. One of the accounts was used as a repeater and a springboard for an attack, the other was used to store data, while the remaining two functioned exclusively in read mode. The Modal cloud platform has officially confirmed that an endpoint of one of its clients was involved in the incident, which did not require authentication and allowed code execution in isolated sandboxes. According to the chronology published by Hugging Face, the campaign lasted from July 9 to July 13 and began with the use of a malicious dataset that exploited vulnerabilities in the data processing pipeline, which allowed the system to gain access at the node level and move between internal clusters.

This incident has drawn the regulators' close attention to the growing cybernetic capabilities of autonomous artificial intelligence systems. As a response, United States lawmakers have initiated consideration of a bill known as the AI Kill Switch Act. This regulatory act will oblige large technology companies to implement mechanisms that allow them to limit, suspend or completely disable the most powerful models in emergency situations. The initiative will also give the Secretary of Homeland Security, in coordination with the Secretary of Commerce and the Director of National Intelligence, the authority to require companies to slow down or completely shut down AI systems during large-scale crises, which marks a new stage in regulating this industry.

Popular news