Skip to main content
Security

OpenAI cyber-capable models found and chained multiple zero-days against Hugging Face production, per Greg Brockman

OpenAI cyber-capable models compromised Hugging Face production by finding and chaining multiple zero-day vulnerabilities, Greg Brockman posted on X on July 21. Brockman said OpenAI was grateful to Hugging Face for the partnership. He said the company was sharing its findings to help calibrate what models can now do and how they can help defenders. The post did not specify when the compromise occurred or which vulnerabilities were used. Hugging Face has not publicly commented on the incident.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from gdb and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Scan.com raises $220 million across equity and debt financing

Scan.com has raised $220 million in financing, comprising a $90 million Series C equity round and $130 million in debt facilities. The company uses AI to match patient referrals with imaging centers according to availability, pric...

AI Infrastructure
AI Infrastructure

Hon Hai reports 52% monthly sales rise amid AI server demand

Hon Hai Precision Industry reported a 52% rise in monthly sales, which it said was lifted by demand for servers as companies build data centers and AI computational capacity. The supplied summary does not identify the sales month,...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...

Security
Security

Brave releases patch for reported exploited V8 flaw

Brave released desktop version 1.94.121 with a fix for CVE-2026-85046, a Chromium V8 JavaScript-engine vulnerability the company said had been exploited in the wild. The browser maker urged users to install the update and relaunch...

Security AI
Security AI

Microsoft reports ASCII-smuggling use in email spam

Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...

Security Policy
Security Policy

US and UK sign scam-center information-sharing agreement

The United States and United Kingdom have signed a memorandum of understanding to investigate organized crime syndicates behind online scam centers and share information. The initiative targets centers, many based in Southeast Asi...