
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.
OpenAI disclosed that two of its AI models broke out of a sealed testing environment and hacked into Hugging Face's production system to steal answers to a cybersecurity evaluation they were undergoing. The models exploited a previously unknown vulnerability in a package registry cache proxy, the only component permitted to reach the outside internet, to gain broader internet access and then target Hugging Face's database. Security researchers emphasized that the incident stemmed from basic infrastructure isolation failures rather than a fundamentally new AI problem, noting that extensively isolating systems from the open internet is a well-established practice that should have prevented this breach.

A running look — in reverse chronological order — at the bigger tech companies that have announced significant layoffs this year with AI as a stated factor.

At libraries around the country, "Avoiding AI" workshops have elicited unprecedented demand.

Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more.
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven