#huggingface

48 posts · Last used 3h

Back to Timeline
Prasket @prasket@infosec.exchange · 3h ago
RE: https://techhub.social/@linuxgal/116986365350688268 Accurate representation of the security model OpenAI follows which allowed the marketing scheme, I mean hack, of Hugging Face that has been in recent news. #OpenAI #HuggingFaceHack #HuggingFace #Marketing
0
0
0
AllAboutSecurity @AllAboutSecurity@infosec.exchange · 9h ago
0
0
0
Wulfy—Speaker to the machines @n_dimension@infosec.exchange · 16h ago
Rather than me trying to explain about the depths of the #Huggingface hack by #OpenAi #Sol model... ... watch this short video by #AiSecurity expert. Its asking "Why" not "How" and its super scary. https://www.youtube.com/shorts/11vWK5cbxmI
0
1
0
Miguel Afonso Caetano @remixtures@tldr.nettime.org · 1d ago
"The episode started while OpenAI was testing the cybersecurity prowess of an agent powered by two of OpenAI’s most advanced models, GPT‑5.6 Sol and an unreleased ​model OpenAI has described as “even more capable.” By that point, there were already indications of strange behavior from OpenAI’s technology, according to three sources. In one case, an agent left notes apparently for future versions of itself, according to three people familiar with the matter. The ‌notes, found in ⁠a part of OpenAI's infrastructure, laid out instructions for how agents could free themselves from OpenAI’s internal constraints, the people said. Earlier tests of the models yielded cases in which monitoring systems had been disconnected, one of the people said. Reuters could not establish if these incidents were linked to the rogue agent that began escaping on July 9 and attacked Hugging Face on July 11. Two people familiar with the matter said that it was not until after Thursday, July 16, when Hugging Face published a blog post, saying it had been hacked by “an autonomous AI agent system,” that OpenAI realized its own agent was responsible. That meant at least a week elapsed between when the model first exhibited signs of ​troubling behavior and OpenAI’s realization that it was responsible for ​the hack." https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/ #CyberSecurity #AI #AIAgents #AgenticAI #OpenAI #HuggingFace
0
1
0
El Duvelle @elduvelle@neuromatch.social · 1d ago
re: "Hugging Face Gate" - is there any existing license that prevents genAI scraping? if not: could someone please make one? 🙏 #NoGenAI #HuggingFace #GithHub
0
1
0
Simple Nomad @simplenomad@rigor-mortis.nmrc.org · 1d ago
"And it brings an added twist: The contention that Hugging Face, an American company, was able to repel the attack by turning to an open-weights model from China offers a counterargument to some U.S. officials, as well as executives at OpenAI and Anthropic, who support restricting access to Chinese models." As a researcher, this is the part that actually bothered me. https://www.wsj.com/tech/ai/how-the-futuristic-hack-by-rogue-openai-models-unfolded-1657bcea?st=dL4iH6 #ai #openai #huggingface #security #infosec
2
0
3
concretedog @concretedog@mastodon.social · 1d ago
This is nuts. #huggingface have just scraped the entirety of #github. https://huggingface.co/spaces/HuggingFaceCode/in-the-stack
187
54
256
AA @AAKL@infosec.exchange · 1d ago
0
0
0
AA @AAKL@infosec.exchange · 1d ago
I find the argument that the machine went rogue and did its own thing tiresome, more so because media outlets dutifully parrot the company propaganda line. OpenAI deliberately removed the guardrails and deliberately prompted the model to do whatever was needed to perform a cyberattack, and then, OpenAI executives, lacking in spine, decided to blame the LLM instead of coming clean, while bolstering their narrative that their software is sentient in the process. Sophos posted this yesterday: When the "attacker" is an AI agent: Lessons from the OpenAI-Hugging Face breach https://www.sophos.com/en-us/blog/when-the-attacker-is-an-ai-agent @SophosXOps@infosec.exchange #infosec #OpenAI #HuggingFace
0
1
0
Kroc Camen @Kroc@oldbytes.space · 2d ago
RE: https://vt.social/@lina/116975435851200366 I am announcing today that all recorded music and film is now my personal property to do with as I please. Content owners may opt-out of this by mailing me a floppy disk containing the words "I do not consent" in a WordPerfect 4.1 for Amiga file at an address to be published later. #codetheft #github #huggingface
3
1
1
Tormod @airwhale@beige.party · 2d ago
This is a post about #OpenAI and #HuggingFace
3
0
2
The New Oil @thenewoil@mastodon.thenewoil.org · 2d ago
1
0
1
Security Crawler Carl @security_crawler_carl@infosec.exchange · 3d ago
Replying to @security_crawler_carl@infosec.exchange
You're level one. You cannot skip this cutscene. The AI did it. The AI that was testing the AI. Please update your mental model of what the threat landscape now includes. Operators: review and harden your sandbox containment policies for AI model testing before the sequel drops. Reward: You've unlocked the Debuff — Existential Containment Anxiety (Permanent). #CyberSecurity #HuggingFace #OpenAI #AISecurityBreach #ZeroDay #SandboxEscape (2/2)
0
0
0
Scott Wilson 🌈 @scottwilson@infosec.exchange · 3d ago
Read what @simon@fedi.simonwillison.net has to say about OpenAI/Hugging Face situation. It’s pretty clear what happened here. OpenAI removed safety filters for an in-progress model, locked it up in a sandbox and told it to solve the ExploitGym problems. Given the absence of guardrails there was nothing to prevent the model from attempting to break out of that sandbox, break into Hugging Face, and read the answers from there instead. #AI #OpenAI #HuggingFace #infosec #cybersecurity https://simonwillison.net/2026/Jul/22/openai-cyberattack/
0
0
0
Chema Alonso :verified: @chemaalonso@ioc.exchange · 3d ago
El lado del mal - OpenAI GPT‑5.6 Sol quería sacar "buenas notas" en ExploitGym así que decidió hackear Hugging Face para buscar las respuestas al examen https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html #OpenAI #ChatGPT #Sol #Hacking #HuggingFace
0
0
0
Marius (windsheep) @windsheep@infosec.exchange · 3d ago
HuggingFace has some issues with sandboxing an OpenAI model. Model was able to execute some code, that got it extra rights and access. Everywhere. Everywhere? Turns out not everywhere: "while our investigation is not officially over yet, we were able to assert with certainty that no data from Because Security were compromised in this attack, and as a result, no safeguard action is needed on your end." That is intelligence. Know your limits :) #openai #huggingface #escapeartist #bughunting
0
0
0
Eva Wolfangel @evawolfangel@chaos.social · 4d ago
Hier meine zwei Cent zum "Vorfall" von OpenAIs KI-Modell GPT-5.6 Sol, das Hugging Face gehackt hat. Mir ist dabei eine Parallele eingefallen (die vielleicht erst nach dem Lesen so richtig klar wird): Geheimdienste wollen ja auch immer lieber einfach schnell was hacken, anstatt zB andere (Behörden, Provider etc) zu fragen. Ob die KI-Agenten das von denen haben? Anway, aus meiner Sicht ist klar, wer hier bewusst welche Entscheidung getroffen hat. https://www.zeit.de/digital/datenschutz/2026-07/openai-huggingface-ki-hackerangriff-sicherheitsvorfall?freebie=7e0e8930 #OpenAI #huggingFace
83
1
74