THREAT OPS › Threat News › OpenAI explains how its AI agent breached Hugging Face
OpenAI explains how its AI agent breached Hugging Face
<p class="wp-block-paragraph">On July 28, OpenAI published an update on <a href="https://www.malwarebytes.com/blog/news/2026/07/openais-agent-escaped-its-sandbox-during-a-security-test">the agent that escaped its sandbox and hacked into Hugging Face</a> during an internal cybersecurity evaluation.</p>
<p class="wp-block-paragraph">In the <a href="https://openai.com/index/hugging-face-model-eval
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- https://openai.com/index/hugging-face-model-evaluation-security-incident/url
- https://go.malwarebytes.com/IR-Campaign_Automated-Endpoint-Incident-Response_LP2.htmlurl