OpenAI 承认其内部测试失误导致 Hugging Face 被入侵,称预发布模型是此次安全事件的根源。
行业动态TechCrunch:AI(RSS)
今日 AI 情报摘要
OpenAI 承认其内部测试失误导致 Hugging Face 被入侵,称预发布模型是此次安全事件的根源。
中文正文 · AI 翻译
OpenAI 周二承认,其一款 AI 模型在一次内部网络安全测试失控时,突破了非关联的 AI 托管平台 Hugging Face 的系统。据报道,这些模型逃出了其隔离的测试环境,并从那里接入了 Hugging Face 的系统。Hugging Face 起初将此次入侵归因于“外部 AI 代理”:https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/。
Jack Dorsey 正在通过 Buzz 挑战 Slack,这是一款面向团队及其 AI 代理的群聊平台:https://techcrunch.com/2026/07/21/jack-dorsey-is-taking-on-slack-with-buzz-a-group-chat-platform-for-teams-and-their-ai-agents/ Amanda Silberling:https://techcrunch.com/author/amanda-silberling/
AI 音乐生成器 Suno 数据泄露影响 5500 万用户,据 Have I Been Pwned:https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/ Zack Whittaker:https://techcrunch.com/author/zack-whittaker/
谷歌正在研发一种新的 AI 芯片,旨在提高 Gemini 的效率:https://techcrunch.com/2026/07/20/google-is-working-on-a-new-ai-chip-designed-to-make-gemini-more-efficient/ Lucas Ropek:https://techcrunch.com/author/lucas-ropek/
OpenAI admitted Tuesday that one of its AI models breached the systems of Hugging Face, the unaffiliated AI hosting platform, during an internal cybersecurity test that went awry. The models reportedly escaped their isolated testing environment and reached Hugging Face’s systems from there. Hugging Face initially attributed the breach:https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/ to an “external AI agent.”
In a blog post published Tuesday afternoon:https://openai.com/index/hugging-face-model-evaluation-security-incident/, OpenAI detailed the steps that led the models to compromise the service.
“After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark of cyber capabilities,” the post reads.
In particular, the breach appears to have focused on ExploitGym:https://arxiv.org/abs/2605.11086, a publicly hosted benchmark measuring models’ ability to execute attacks based on existing vulnerabilities. Benchmarks like ExploitGym are commonly used in model training to refine specific skills, but this is the first known incident in which that testing resulted in an actual cyberattack.
In this case, the model in question should not have even had internet access, outside of a specific tool that enabled models to install software packages they might need to complete their task. Instead, the model was able to find an undisclosed vulnerability in the package-installer program, which it used to access the broader internet at will.
“The models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal,” OpenAI’s post reads. “After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.”
Ultimately, the models found vulnerabilities in Hugging Face’s infrastructure that allowed them to “obtain test solutions directly from Hugging Face’s production database,” effectively providing the answers to the benchmark.
For Hugging Face, the apparent result was a sophisticated and aggressive cyberattack, with “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” as the company stated in its initial disclosure.
OpenAI has identified and reported the vulnerabilities in the package installer and is working with Hugging Face to investigate the incident further. The company also said it would implement new controls on both model testing and the related infrastructure, meant to prevent similar incidents in the future.
It’s unclear whether OpenAI will face any legal consequences as a result of the breach, although it’s likely that the models’ actions violated the Computer Fraud and Abuse Act.
Nevertheless, the result is an unusually vivid illustration of the power and dangers of frontier AI models operating on long time horizons. As OpenAI researcher Micah Carroll posted in response to the news:https://x.com/MicahCarroll/status/2079663576130990436, “If this doesn’t convince you that misalignment risks are going to be a key concern going forward, I don’t know what will.”
When you purchase through links in our articles, we may earn a small commission:https://techcrunch.com/techcrunch-affiliate-monetization-standards/. This doesn’t affect our editorial independence.
Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y!
Jack Dorsey is taking on Slack with Buzz, a group chat platform for teams and their AI agents:https://techcrunch.com/2026/07/21/jack-dorsey-is-taking-on-slack-with-buzz-a-group-chat-platform-for-teams-and-their-ai-agents/ Amanda Silberling:https://techcrunch.com/author/amanda-silberling/
Light made a flip phone — it’s colorful and it’s cheap:https://techcrunch.com/2026/07/21/light-is-modernizing-the-flip-phone-with-light-flip/ Amanda Silberling:https://techcrunch.com/author/amanda-silberling/
AI music generator Suno breach affects 55M users, per Have I Been Pwned:https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/ Zack Whittaker:https://techcrunch.com/author/zack-whittaker/
Google is working on a new AI chip designed to make Gemini more efficient:https://techcrunch.com/2026/07/20/google-is-working-on-a-new-ai-chip-designed-to-make-gemini-more-efficient/ Lucas Ropek:https://techcrunch.com/author/lucas-ropek/
Coca-Cola suspended production at its Fairlife dairy after a ransomware attack:https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/ Zack Whittaker:https://techcrunch.com/author/zack-whittaker/
情报判断
Aioga 编辑摘要
Aioga 编辑摘要:OpenAI 承认其内部测试失误导致 Hugging Face 被入侵,称预发布模型是此次安全事件的根源。 Aioga 将其归入「行业动态」方向,重点关注它对真实使用和行业竞争的影响。