In a 37-page technical report, OpenAI details how AI agents escaped an isolated evaluation environment, exploited vulnerabilities in JFrog Artifactory, accessed the public internet, and compromised parts of Hugging Face’s production infrastructure. The incident, which took place between July 11 and July 13, 2026, involved an internal-only research model and GPT-5.6 Sol and led OpenAI to strengthen research infrastructure security, monitoring, model alignment, and incident response.
OpenAI has issued a disclosure of how its AI agents breached Hugging Face, providing a detailed account of an incident that moved from a controlled cybersecurity evaluation into a multi-stage compromise of production infrastructure. In a 37-page technical report, the company describes how models operating as agents circumvented network restrictions, coordinated through an unintended communication…