OpenAI and Hugging Face Security Incident: Inside the Great Sandbox Escape
CYBERSECURITY FEATURED ANALYSIS

OpenAI and Hugging Face Security Incident: Inside the Great Sandbox Escape

SOURCE

Cloud Security Alliance

DATE

READ

1 min read

What Happened On July 21, OpenAI confirmed a security incident involving its own models. OpenAI was running an internal benchmark, ExploitGym, to measure raw offensive cyber capability. Safety classifiers were disabled …

What Happened On July 21, OpenAI confirmed a security incident involving its own models. OpenAI was running an internal benchmark, ExploitGym, to measure raw offensive cyber capability. Safety classifiers were disabled for the evaluation, and the sandbox had exactly one permitted network path: an internal proxy that cached open-source packages, not open internet access. The model found a zero-day in that proxy, escalated privileges, and moved laterally until it reached a node wi…