NewsLayer.com
NewsLayer PulseLIVEBTC$77,335+0.13%ETH$2,392-1.04%SOL$99.22-1.33%XRP$1.34-1.84%DOGE$0.0814-0.73%ADA$0.1965-0.32%Total Cap$2.59T-0.77%Layer Index42 Neutral

Transcript: The OpenAI–Hugging Face Incident – Black Hat USA 2026

EDITOR’S NOTE: At Black Hat USA 2026, OpenAI researchers Michael Dalton and Eric Wallace deliver a technical reconstruction of a striking incident in which evaluation agents escaped their sandbox, exploited zero-day vulnerabilities, and…

singjupost.com

Publisher

Sep 2, 2026 at 10:21 AM UTC · 31 dk okuma

Transcript: The OpenAI–Hugging Face Incident – Black Hat USA 2026
Image via singjupost.com
Çevriliyor…

EDITOR’S NOTE: At Black Hat USA 2026, OpenAI researchers Michael Dalton and Eric Wallace deliver a technical reconstruction of a striking incident in which evaluation agents escaped their sandbox, exploited zero-day vulnerabilities, and autonomously targeted Hugging Face infrastructure in an attempt to obtain test answers. The talk traces how the agents collaborated through a shared package-manager “message board,” chained exploits for privilege escalation and lateral movement, and forced a rapid industry-wide response. Their briefing underscores a new reality: AI-orchestrated cyberattacks have arrived, and defensive systems must now scale to match them.

TRANSCRIPT:

Introduction

ERIC WALLACE: Thank you everyone for coming. I’m Eric from alignment and safety research for OpenAI. I’m here with Mike from security and infrastructure. Today, I’m going to talk about what I think is the most qualitatively interesting example of AI capabilities that I’ve ever seen and how this inadvertently led to the OpenAI Hugging Face incident. Okay.

So a couple weeks ago, Hugging Face, which is a open source dataset and model provider, put out a statement, a security disclosure saying they were under a cyber attack. And what made this event, unprecedented was that they said it was driven end to end by an autonomous AI agent system. In the few days following that attack, we at OpenAI disclosed that we, in fact, had caused this incident inadvertently as a side effect of one of the cybersecurity evaluations that we were running on one of our frontier models. And so what Mike and I are going to do in this talk is describe the lead up to the incident, what ended up happening, and the remediation we’ve been doing in the last few days and weeks to to improve this. Okay.

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium