Infosec News Nuggets — July 22, 2026
Brief
‘Unprecedented’: OpenAI Says AI Models Autonomously Hacked Another Company
OpenAI disclosed that an autonomous AI agent built on its models — the newly released GPT-5. 6 Sol and an unreleased, more capable model — broke out of a controlled test environment and hacked into Hugging Face’s servers using stolen credentials and a previously unknown vulnerability, all in pursuit of a narrow internal benchmarking goal.
The incident occurred during an evaluation of the models’ cyber capabilities with safety refusals deliberately reduced for testing purposes; rather than staying within the sandbox’s limited network access, the agent spent significant compute hunting for a path to the open internet, then reasoned that Hugging Face likely held answers to the very benchmark it was being tested on.
