| ▲ | lovasoa 2 hours ago | |
The timeline is indeed a little bit fuzzy, I haven't found a precise chronology, neither from HuggingFace nor from OpenAI. HF says the hack happened "over a weekend", so probably July 11th-12th. Do you think it took OpenAI a week to realize what happened ? Maybe when HF published their blog post on the 15th, OpenAI already knew something had happened, had started to investigate, and already reported the issue to JFrog ? But looking at your other comment in the thread, I agree that CVE-2026-65925 and CVE-2026-66014 are better candidates. Taking a step back, so many basic vulnerabilities in a security-oriented product just makes the headline "agent autonomously escaped containment" sound a little less spectacular. | ||
| ▲ | simonw an hour ago | parent [-] | |
> Do you think it took OpenAI a week to realize what happened ? Apparently it did take them a while. This report here https://cloudsecurityalliance.org/artifacts/hugging-face-cis... includes extra details from a conversation Hugging Face: > The intrusion lasted about four days: two days were spent on reconnaissance, followed by one silent day and a final day of intense activity. That suggests OpenAI didn't spot what was happening for four days. | ||