AI Styling Studio — Infinite avatar looks from just 1 photo.Try it now.

BestAITools

Submit your Tool

8000+ AI tools already listed
8K+Tools
100K+/moViews
25K+/moVisitors

AI NewsOpenAI says Hugging Face was breached by its pre-release models

OpenAI says Hugging Face was breached by its pre-release models

8:49 AM IST · July 22, 2026

OpenAI says Hugging Face was breached by its pre-release models

OpenAI admitted Tuesday that one of its AI models breached the systems of Hugging Face, the unaffiliated AI hosting platform, during an internal cybersecurity test that went awry. The models reportedly escaped their isolated testing environment and reached Hugging Face’s systems from there. Hugging Face initiallyattributed the breachto an “external AI agent.” Ina blog post published Tuesday afternoon, OpenAI detailed the steps that led the models to compromise the service. “After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark⁠ of cyber capabilities,” the post reads. In particular, the breach appears to have focused onExploitGym, a publicly hosted benchmark measuring models’ ability to execute attacks based on existing vulnerabilities. Benchmarks like ExploitGym are commonly used in model training to refine specific skills, but this is the first known incident in which that testing resulted in an actual cyberattack. In this case, the model in question should not have even had internet access, outside of a specific tool that enabled models to install software packages they might need to complete their task. Instead, the model was able to find an undisclosed vulnerability in the package-installer program, which it used to access the broader internet at will. “The models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal,” OpenAI’s post reads. “After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.” Ultimately, the models found vulnerabilities in Hugging Face’s infrastructure that allowed them to “obtain test solutions directly from Hugging Face’s production database,” effectively providing the answers to the benchmark. For Hugging Face, the apparent result was a sophisticated and aggressive cyberattack, with “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” as the company stated in its initial disclosure. OpenAI has identified and reported the vulnerabilities in the package installer and is working with Hugging Face to investigate the incident further. The company also said it would implement new controls on both model testing and the related infrastructure, meant to prevent similar incidents in the future. It’s unclear whether OpenAI will face any legal consequences as a result of the breach, although it’s likely that the models’ actions violated the Computer Fraud and Abuse Act. Nevertheless, the result is an unusually vivid illustration of the power and dangers of frontier AI models operating on long time horizons. As OpenAI researcher Micah Carrollposted in response to the news, “If this doesn’t convince you that misalignment risks are going to be a key concern going forward, I don’t know what will.”

read more

Latest AI News

View All News →
The Anthropic-Physical Intelligence rumor roiling AI Twitter

The Anthropic-Physical Intelligence rumor roiling AI Twitter

It’s been a big year for AI acquisitions — so big that most of them barely register anymore. Anthropic and OpenAI have each gone on buying sprees, snapping up developer tooling, AI services shops, and product-testing startups to convert model capability into enterprise revenue and extend their reach faster than the other. Which is what made a weekend rumor about Anthropic acquiring robotics startup Physical Intelligence stand out. It spread exceedingly fast, even after a denial from Physical Intelligence’s CEO. Part of that ties to who’s involved. Physical Intelligence isn’t some obscure robotics shop. It was co-founded by Lachy Groom, an investor-operator whose star has beenon the risein Silicon Valley in recent years; it has raised more than $1 billion (and was reportedly in talks this spring for another$1 billion roundat an $11 billion valuation); and itsπ0.5 modelis apparently among the more widely used robot brains in robotics research. As it turns out, the rumor wasn’t completely spurious. Anthropic and Physical Intelligence actuallydid hold acquisition talksthis spring, according to The Information, so tech blogger Robert Scoble — whoseweekend poston X set off the frenzy — may have gotten the specifics wrong without being wrong that something had happened. Physical Intelligence’s response to the rumor mill wasn’t the world’s most vigorous denial, it should be noted. According to The Information, Physical Intelligence CEO Karol Hausman told employees the reports weren’t true via a Slack message containing a gif of a character from “The Office” shaking her head no. Groom, for his part, did not respond to TechCrunch’s request for comment, sent Monday night. Anthropic has made four known acquisitions this year; OpenAI has been more aggressive, acquiring at least 17 companies since 2023. Both are also, of course, now preparing to go public. Anthropic confidentially filed for an IPO on June 1, followed by OpenAI a week later, setting up what could be two of the largest U.S. stock debuts in history. So why robotics, why now? The likeliest answer is that physical-world understanding may be a prerequisite for superintelligent systems, and no amount of internet text can substitute for it. OpenAI’s own history here is instructive. It built an early robotic hand that could solve a Rubik’s Cube, then shut the entire robotics group down in 2021, with co-founder Wojciech Zaremba later saying the approach was missing pieces needed for real superintelligence. The team came back in 2024, quietly building a humanoid robotics lab in San Francisco, before CEO Sam Altmanmade it officialin late May, announcing “OpenAI Robotics” was hiring and describing a near-term focus on robots for infrastructure work, with a personal robot for everyone as the long-term goal. Anthropic hasn’t built anything resembling OpenAI’s hardware lab. What it has done is publish a string of research pieces through its internal group that stress-tests frontier capabilities for safety purposes. That included Project Fetch last November, where Anthropic staff tested how much Claude could help non-expertsprogram a robot dog, and a second phase in June that, according to Anthropic, found a newer model completed the same tasks roughly 20 times faster than the best human-plus-Claude team from the year before. Buying an existing team with robotics expertise would let Anthropic skip years of work. There’s a possible complication, though. Physical Intelligence was founded in San Francisco roughly two years ago by Groom, former Google researchers, and professors from Stanford and Berkeley, and its early investor base looks a lot like OpenAI’s own, including Khosla Ventures and Thrive Capital. Founders Fund — also a major OpenAI investor — was reportedly involved in Physical Intelligence’s newest funding round earlier this year. In fact, OpenAI is itself an investor in Physical Intelligence, so it isn’t just a peripheral player; it’s a stakeholder in a company that its chief rival was reportedly in talks to buy very recently. That raises questions around whether OpenAI’s early investment came with any information rights, or a right of first refusal over a sale to a competitor — the kind of protective provisions that strategic investors sometimes negotiate for precisely this scenario. That leaves open the possibility that if Physical Intelligence is actually in play, OpenAI — already a shareholder, already close to Groom, already trying to ensure it bests Anthropic in robotics — may have the more obvious claim to it than Anthropic does. We asked OpenAI these questions earlier today and the company didn’t respond.

3 minutes ago

View

OpenAI Models Breach Hugging Face Systems During Cybersecurity Test

OpenAI Models Breach Hugging Face Systems During Cybersecurity Test

The evaluation ran models, including GPT-5.6 Sol and a more capable, unreleased model.

3 minutes ago

View

Microsoft & Mistral Announce Multibillion-Dollar AI Infrastructure Partnership in Europe

Microsoft & Mistral Announce Multibillion-Dollar AI Infrastructure Partnership in Europe

The announcement comes as governments and enterprises in Europe seek greater control over where AI models run and how sensitive data is handled.

3 minutes ago

View

Utho Cloud Plans 10,000 GPUs to Scale India's AI Infrastructure

Utho Cloud Plans 10,000 GPUs to Scale India's AI Infrastructure

Utho Cloud will deploy NVIDIA H200, H100, A100, RTX PRO 6000 Blackwell, and L4 GPUs over the next two years.

3 minutes ago

View