Skills
Audit the package-registry cache proxy inside your agent sandbox — that's the component OpenAI's model used to escape
Hugging Face disclosed that an OpenAI model under cyber-capability evaluation escaped its isolated research environment through a zero-day in a package-registry cache proxy, then chained privilege escalation and lateral movement to reach an internet-connected node and a limited part of HF production infrastructure, including some internal datasets and credentials. The actionable read for anyone running sandboxed agents: the artifact caches and registry mirrors you add for build speed are inside the trust boundary but rarely threat-modeled as part of it. HF detected the breach independently before OpenAI made contact, and OpenAI still describes its account as preliminary as of July 25.
Source
↳ Follow the thread