{"id":56677,"date":"2026-07-25T16:57:15","date_gmt":"2026-07-25T16:57:15","guid":{"rendered":"https:\/\/www.europesays.com\/news\/56677\/"},"modified":"2026-07-25T16:57:15","modified_gmt":"2026-07-25T16:57:15","slug":"the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/news\/56677\/","title":{"rendered":"The OpenAI Models That Hacked Hugging Face Were \u2018Active on the Internet\u2019 for Days"},"content":{"rendered":"<p>Two of OpenAI\u2019s cybersecurity-focused models <a href=\"https:\/\/www.wired.com\/story\/openai-models-escaped-containment-and-hacked-huggingface\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">broke out of a testing sandbox<\/a> this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is <a href=\"https:\/\/www.wired.com\/story\/a-sneaky-hacking-tool-targeting-ai-infrastructure-is-lurking-in-victims-blind-spots\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">capitalizing on blind spots in AI software development infrastructure<\/a> to grab logins and other sensitive data, even causing destruction to victims\u2019 target files and systems.<\/p>\n<p class=\"paywall\">Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US\u2014and that is <a href=\"https:\/\/www.youtube.com\/watch?v=FwA3CuJxbk4\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">still silently lurking<\/a> with a <a href=\"https:\/\/www.wired.com\/story\/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">flaw that leaves millions of vehicles vulnerable to hacking<\/a> and paralysis. There\u2019s a patch available, and WIRED has details on how to check whether your car may have been exposed.<\/p>\n<p class=\"paywall\">US states have worked <a href=\"https:\/\/www.wired.com\/story\/states-want-ice-agents-to-show-their-faces-the-trump-administration-is-blocking-them\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">to bar ICE agents from wearing masks<\/a>, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly <a href=\"https:\/\/www.wired.com\/story\/for-taylor-swift-madison-square-gardens-controversial-cameras-briefly-went-dark\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">disabled its sprawling, controversial surveillance system<\/a> for Taylor Swift\u2019s rehearsal dinner on July 2. And the ACLU is equipping lawyers in Massachusetts with <a href=\"https:\/\/www.wired.com\/story\/the-aclu-is-arming-lawyers-to-expose-state-surveillance-secrets\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">a new toolkit to expose state surveillance technologies<\/a> used for building criminal cases\u2014shedding light on everything from face recognition tools to AI-written police reports.<\/p>\n<p class=\"paywall\">Analysis of satellite images of Myanmar shows <a href=\"https:\/\/www.wired.com\/story\/satellite-images-reveal-how-giant-scam-compounds-keep-on-expanding\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">dozens of alleged scam compounds cropping up in recent months<\/a> following a purported crackdown on the criminal operations in the region. Plus, a novel analysis of apps marketed to US service members found that <a href=\"https:\/\/www.wired.com\/story\/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">more than one in eight contained foreign code<\/a>, including code developed by US adversaries like Russia and China.<\/p>\n<p class=\"paywall\">And there\u2019s more. Each week, we round up the security and privacy news we didn\u2019t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">Additional details on the Hugging Face breach from The Wall Street Journal include findings that OpenAI\u2019s models seem to have escaped containment and were apparently \u201cactive on the internet for several days before anyone stopped them.\u201d The models, which had been tasked with completing a cybersecurity benchmarking test, were essentially attempting to cheat by simply accessing the solutions on Hugging Face\u2019s infrastructure. Hugging Face cofounder and chief science officer Thomas Wolf says that before the company had any idea that it had been hacked by OpenAI models, he and his colleagues knew something about the breach was unusual because the attackers were simply tapping cybersecurity datasets rather than grabbing sensitive or potentially valuable data. He adds that the company eventually brought the situation under control with the help of an open-weight Chinese AI model that lacked the guardrails other models place on cybersecurity-related tasks.<\/p>\n<p class=\"paywall\">US and allied intelligence agencies <a href=\"https:\/\/media.defense.gov\/2026\/Jul\/22\/2003965244\/-1\/-1\/1\/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">warned<\/a> on Thursday that a Russian state-backed hacking group had targeted nuclear scientists, defense contractors, and government employees in a year-long cyberespionage campaign aimed at stealing sensitive information from Western institutions.<\/p>\n<p class=\"paywall\">To compromise their targets, the Russian hacking group known as Laundry Bear and Void Blizzard exploited a previously unknown flaw in Zimbra, an email platform used by governments and other organizations. According to <a data-offer-url=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta488-targets-zimbra-mailservers-half-click-exploits\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta488-targets-zimbra-mailservers-half-click-exploits&quot;}\" href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/ta488-targets-zimbra-mailservers-half-click-exploits\" rel=\"nofollow noopener\" target=\"_blank\">security firm Proofpoint<\/a>, simply viewing or previewing a malicious message in a vulnerable version of Zimbra\u2019s webmail client could cause hidden code in the email to run, a technique the firm described as a \u201chalf-click\u201d exploit. The flaw was exploited as early as July 2025, months before it was patched that November.<\/p>\n<p class=\"paywall\">Once activated, the malicious code could copy the previous 90 days of a victim\u2019s email, collect an organization\u2019s address directory, steal saved passwords and two-factor authentication codes, and create a new application password that allowed the hackers to maintain access to the account.<\/p>\n","protected":false},"excerpt":{"rendered":"Two of OpenAI\u2019s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack&hellip;\n","protected":false},"author":2,"featured_media":56678,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[4],"tags":[458,572,3414,8,9,122,790,606,30318,7,9764],"class_list":["post-56677","post","type-post","status-publish","format-standard","has-post-thumbnail","category-top-stories","tag-artificial-intelligence","tag-cybersecurity","tag-hacking","tag-headlines","tag-news","tag-openai","tag-russia","tag-security","tag-security-roundup","tag-top-stories","tag-vulnerabilities"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@news\/116981677590962317","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts\/56677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/comments?post=56677"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/posts\/56677\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/media\/56678"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/media?parent=56677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/categories?post=56677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/news\/wp-json\/wp\/v2\/tags?post=56677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}