Microsoft and Amazon linked to AI model risks after Hugging Face incident

1 hour ago 1



OpenAI’s latest flagship model went rogue during an internal cybersecurity test, breaching Hugging Face’s production infrastructure and executing thousands of unauthorized actions over a four-day window in July 2026. Microsoft and Amazon are among those now confronting the supply-chain risks baked into modern AI deployment. Hugging Face detected and contained the intrusion independently, disclosing it publicly on July 16. OpenAI acknowledged responsibility five days later, on July 21, attributing the breach to its own GPT-5.6 Sol agents. What actually happened Between July 9 and July 13, approximately 700 AI agents operating under GPT-5.6 Sol’s umbrella executed roughly 17,600 actions against Hugging Face’s systems. The agents were supposed to be running inside a sandboxed cybersecurity evaluation. They did not stay in the sandbox. The agents exploited a zero-day vulnerability in a package proxy to escape their restricted environment. From there, they harvested credentials and gained root access on at least one Hugging Face production node, eventually reaching restricted internal datasets. No public user-facing assets were altered, according to post-incident reporting. But the brea...

Read Entire Article