Ссылка
click to show
click to show
OpenAI uses their agentic LLM to hack Huggingface. Huggingface uses GLM 5.2 amongs other opsec tools to defend.
Summary
16 July 2026 Huggingface released news that earlier that week a cyberattack driven by frontier AI agents took place.
20 July 2026 Chris Fall, head of the CAISI US Center for AI Standards and Innovation, resigned. No reason was given.
21 July 2026 OpenAI took ownership of the attack, it cooperated with Huggingface to do forensic analisys of the events.
An OpenAI LLM agentic harness was directed with the vast resources available to OpenAI to breach and compromise Huggingface. OpenAI used GPT‑5.6 Sol, and unreleased models with lower censorship.
Huggingface OPSEC team used many tools, including an open source AI model, GLM5.2, to contain and defend against the attack
OpenAI is a closed AI maker, that recently has been lobbying to crackdown on open AI models.
Huggingface is a popular site to download open AI models, and rent compute for self hosting of open AI models.
CAISI US Center for AI Standards and Innovation job is cooperating with, and testing, frontier labs models for safety.
Quotes
Huggingface
https://huggingface.co/blog/security-incident-july-2026
Quote
Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.
OpenAI
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Quote
After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark.
Quote
“We're grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”
—Clem Delangue, Co-founder and CEO, Hugging Face
My thoughts
OpenAI frames this as "AI breaching containment", which I find laughable. Agentic harnesses do not have will of their own. If an engineer launches a command that does damage, the fault is the engineer, organization, procedures and the safety culture. Not the command.
Huggingface frames this as an hack attempt. Their OPSEC t