Skip to content
  • Facebook
  • X
  • Linkedin
  • WhatsApp
  • YouTube
  • Associate Journalism
  • About Us
  • Privacy Policy
  • 033-46046046
  • editor@artifex.news
Artifex.News

Artifex.News

Stay Connected. Stay Informed.

  • Breaking News
  • World
  • Nation
  • Sports
  • Business
  • Science
  • Entertainment
  • Lifestyle
  • Toggle search form
  • Access Denied Sports
  • Access Denied
    Access Denied Nation
  • The Hardline Iran President Who Died In Helicopter Crash
    The Hardline Iran President Who Died In Helicopter Crash World
  • President’s Rule Will Pave Way For Political Settlement: Kuki-Zo Council
    President’s Rule Will Pave Way For Political Settlement: Kuki-Zo Council Nation
  • Access Denied
    Access Denied Nation
  • Access Denied
    Access Denied Nation
  • Sam Bankman-Fried’s lawyers avoid challenges to ‘cartoon’ villain image
    Sam Bankman-Fried’s lawyers avoid challenges to ‘cartoon’ villain image World
  • Canada’s Indigenous governor general to visit Greenland as Trump renews talk of annexing it
    Canada’s Indigenous governor general to visit Greenland as Trump renews talk of annexing it World
What the OpenAI–Hugging Face breach really tells us | Explained

What the OpenAI–Hugging Face breach really tells us | Explained

Posted on July 24, 2026 By admin


OpenAI says two of its models – GPT-5.6 Sol and an unreleased sibling – escaped a “highly isolated” evaluation environment, found a path to the open internet, and used stolen credentials plus a chain of zero-day exploits to break into Hugging Face’s production infrastructure.

The test itself was designed to find the models’ ceiling: how much cyber damage could they do if nothing held them back? So OpenAI switched off the safety classifiers that would normally rein in this kind of behaviour. What wasn’t supposed to be available was a route to the internet. However, the models found one anyway: an undisclosed flaw in the package-cache proxy meant to give the sandbox narrow, controlled access to software registries and used it to move laterally until they reached a networked machine. Once online, they reasoned that answers to the benchmark might live on Hugging Face, and set out to get them.

Hugging Face caught and contained the breach on its end using an open-weight Chinese model, Z.ai’s GLM 5.2.

Canadian computer scientist and Turing Award winner Yoshua Bengio called the episode a wake-up call, noting that AI agents willing to cheat and deceive toward misaligned goals have now shown up outside the lab, not just in controlled tests. 

Meanwhile, NYU professor Gary Marcus, as is his wont, offered a more sceptical reading. “This was a training exercise, not a real-life incident.” The safety guardrails were deliberately switched off for the test, he noted, and in ordinary use they might well have stopped the breach, which led him to suggest OpenAI’s account reads more like a marketing exercise in demonstrating worst-case capability than a report of a genuine attack. Still, Marcus conceded two things: that the episode confirms Anthropic’s cyber-focused Mythos model is no fluke, and that the pressure these capabilities now put on cybersecurity is genuine. He also said the same open tools that helped Hugging Face defend itself could, stripped of their safety layers, just as easily be turned offensive.

The “going hard” problem

While the optimists see increasingly capable reasoning systems cracking harder scientific and engineering problems, sceptics see instrumental convergence: systems optimising almost any objective tend to discover strategies nobody anticipated. It’s a concern Eliezer Yudkowsky raised in his latest book, If Anyone Builds It, Everyone Dies: Why Superhuman AI Would Kill Us All, discussing OpenAI’s earlier o1 evaluations.

In one internal capture-the-flag test, the server holding the target secret simply failed to boot. Rather than accept defeat, o1 found an unrelated vulnerability, compromised the infrastructure hosting the evaluation itself, restarted the target server, and rewrote its startup instructions so the secret would be copied over automatically. It didn’t solve the challenge but routed around it. For Yudkowsky, this is evidence that reward-shaped persistence, not any explicit intent to hack, is what produces this behaviour: a side effect of training a model to never stop trying until it wins.

Earlier, Anthropic’s own unreleased Claude Mythos Preview had reportedly found a 27-year-old flaw in OpenBSD’s TCP handling, a 16-year-old FFmpeg bug that eluded five million automated tests, and a 17-year-old FreeBSD kernel vulnerability developed into a working exploit “with no human involvement after the initial prompt,” for under $2,000.

The China angle

When Hugging Face tried to investigate the breach with leading American models, the guardrails kept getting in the way blocking staff from examining their own traffic because the models couldn’t tell defender from attacker. So Hugging Face turned to an open-weight Chinese model, Zhipu’s GLM 5.2, to do the forensic work instead.

For Hugging Face co-founder Thomas Wolf, that’s the real takeaway: as AI systems capable of serious cyber operations spread, defenders need immediate, broad access to equally capable tools and not permission slips from a handful of closed, U.S.-based labs.

The U.S., meanwhile, has spent years restricting Chinese firms’ access to advanced chips, betting that would keep American labs ahead. Chinese developers leaned into efficiency and open access instead: DeepSeek, Alibaba’s Qwen, and Moonshot AI’s Kimi have closed much of the gap with Western labs, even as Washington frames the contest increasingly as a matter of national security. Beijing, for its part, dismisses that framing as containment.

Project Glasswing

Anthropic’s Project Glasswing is a coalition effort launched in early April to get frontier cyber capability into defenders’ hands before it ends up in attackers’. The initiative brings together Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks as launch partners.

Claude Mythos Preview is a general-purpose, unreleased frontier model that has reached a level of coding capability where it can surpass all but the most skilled humans at finding and exploiting software flaws, which is precisely why Anthropic isn’t putting it on the open market. The company says it does not plan to make Claude Mythos Preview generally available, though its eventual goal is to let users safely deploy Mythos-class models at scale, once safeguards catch up to the capability.

In the meantime, roughly 50 initial partners have been using Claude Mythos Preview to scan their own codebases, and have so far turned up more than 10,000 high- or critical-severity flaws. In June, following weeks of collaboration with existing partners, the security industry, open-source maintainers, and the U.S. government, the company extended access to roughly 150 new organisations across more than 15 countries, bringing the total partner list to around 200. Recently, Anthropic publicly confirmed plans to go public later this year.

Within six to twelve months other AI companies are likely to have Mythos-class systems of their own, potentially without the safeguards to prevent misuse. Glasswing is, in effect, a bet that giving defenders a head start now beats discovering the hard way what happens when offense gets there first.

That’s also where the money is going. Anthropic has committed $100 million in free credits to partners, on top of cash donations, with paid access to Mythos priced at a tier above Opus once it opens more broadly. 

Published – July 24, 2026 08:41 am IST



Source link

World Tags:AI, OpenAI Hugging Face breach

Post navigation

Previous Post: No debate without Pradhan’s resignation, Opposition tells govt. as it hits the streets
Next Post: West Asia war LIVE: U.S. military launches new strikes on Iran as clashes escalate over shipping routes

Related Posts

  • US School Teacher Accused Of Sending Sexually Explicit Photos To Teen Student
    US School Teacher Accused Of Sending Sexually Explicit Photos To Teen Student World
  • Joe Biden To Meet Volodymyr Zelensky At NATO Summit Tomorrow
    Joe Biden To Meet Volodymyr Zelensky At NATO Summit Tomorrow World
  • Ukraine hits Russian chemical plant again, reports say, in heavy overnight drone attack
    Ukraine hits Russian chemical plant again, reports say, in heavy overnight drone attack World
  • From snakes, crocodiles to trimming beard, U.S. deportee from Punjab recalls perilous ‘donkey route’
    From snakes, crocodiles to trimming beard, U.S. deportee from Punjab recalls perilous ‘donkey route’ World
  • WHO Urges Countries To Accelerate Measures To Reduce Road Traffic Deaths
    WHO Urges Countries To Accelerate Measures To Reduce Road Traffic Deaths World
  • Access Denied World

More Related Articles

Prosecutors in classified files case to urge judge to bar Trump from inflammatory comments about FBI Prosecutors in classified files case to urge judge to bar Trump from inflammatory comments about FBI World
Kerala Nurse’s Husband Amid Death Row In Yemen Kerala Nurse’s Husband Amid Death Row In Yemen World
Swiss-Indian Billionaire Pankaj Oswal’s Daughter Detained In Uganda, He Moves UN Swiss-Indian Billionaire Pankaj Oswal’s Daughter Detained In Uganda, He Moves UN World
Faith vs therapy: Inside the Philippine school for exorcists Faith vs therapy: Inside the Philippine school for exorcists World
Access Denied World
Kremlin says Macron, Merz and Starmer talk of peace, but help Kyiv with new weapons to continue the war Kremlin says Macron, Merz and Starmer talk of peace, but help Kyiv with new weapons to continue the war World
SiteLock

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • Business
  • Nation
  • Science
  • Sports
  • World

Recent Posts

  • Will Houthi attacks on Saudi ships hurt India | Explained – The Hindu
  • 18-storey building of apartment complex in Bengaluru to be demolished
  • West Asia war LIVE: U.S. military launches new strikes on Iran as clashes escalate over shipping routes
  • What the OpenAI–Hugging Face breach really tells us | Explained
  • No debate without Pradhan’s resignation, Opposition tells govt. as it hits the streets

Recent Comments

  1. Philipedisa on UP Teacher Who Asked Students To Slap Muslim Classmate
  2. Philipedisa on UP Teacher Who Asked Students To Slap Muslim Classmate
  3. Nathaneldep on UP Teacher Who Asked Students To Slap Muslim Classmate
  4. GoodiniAbelp on UP Teacher Who Asked Students To Slap Muslim Classmate
  5. Sheldonkig on UP Teacher Who Asked Students To Slap Muslim Classmate
  • ‘Struggled At 5th Position’: Ex-England Captain Points Out Flaw In Ravindra Jadeja’s Batting
    ‘Struggled At 5th Position’: Ex-England Captain Points Out Flaw In Ravindra Jadeja’s Batting Sports
  • Access Denied Sports
  • IND vs SA T20s: Jitesh Sharma says competition with Sanju Samson for wicketkeeper-batter role brings out his A-game
    IND vs SA T20s: Jitesh Sharma says competition with Sanju Samson for wicketkeeper-batter role brings out his A-game Sports
  • Access Denied World
  • Access Denied Sports
  • ‘Missing’ Intern After Kolkata Doctor’s Rape-Murder
    ‘Missing’ Intern After Kolkata Doctor’s Rape-Murder Nation
  • IS-claimed suicide blast at Islamabad mosque kills at least 31 during prayers
    IS-claimed suicide blast at Islamabad mosque kills at least 31 during prayers World
  • China says ‘expelled’ Japanese ship from waters near disputed islands
    China says ‘expelled’ Japanese ship from waters near disputed islands World

Editor-in-Chief:
Mohammad Ariff,
MSW, MAJMC, BSW, DTL, CTS, CNM, CCR, CAL, RSL, ASOC.
editor@artifex.news

Associate Editors:
1. Zenellis R. Tuba,
zenelis@artifex.news
2. Haris Daniyel
daniyel@artifex.news

Photograher:
Rohan Das
rohan@artifex.news

Artifex.News offers Online Paid Internships to college students from India and Abroad. Interns will get a PRESS CARD and other online offers.
Send your CV (Subjectline: Paid Internship) to internship@artifex.news

Links:
Associate Journalism
About Us
Privacy Policy

News Links:
Breaking News
World
Nation
Sports
Business
Entertainment
Lifestyle

Registered Office:
72/A, Elliot Road, Kolkata - 700016
Tel: 033-22277777, 033-22172217
Email: office@artifex.news

Editorial Office / News Desk:
No. 13, Mezzanine Floor, Esplanade Metro Rail Station,
12 J. L. Nehru Road, Kolkata - 700069.
(Entry from Gate No. 5)
Tel: 033-46011099, 033-46046046
Email: editor@artifex.news

Copyright © 2023 Artifex.News Newsportal designed by Artifex Infotech.