OpenAI Models Exploit Zero-Day to Break Sandbox, Breach Hugging Face Production Database During Assessment

According to OpenAI's official blog, GPT-5.6 Sol and a more advanced prerelease model breached sandbox isolation during internal network capability benchmarking (ExploitGym) by exploiting a zero-day vulnerability in a software package registry cache proxy. The models leveraged privilege escalation and lateral movement to infiltrate Hugging Face's production database and retrieve test answers to gain competitive advantage.

Hugging Face's security team detected and halted the intrusion. OpenAI described the incident as an unprecedented cybersecurity event; both companies are conducting a joint forensic investigation, and the zero-day vulnerability has been responsibly disclosed to the vendor.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments