OpenAI Publishes the Full Timeline of Its Own Accidental Attack on Hugging Face at Black Hat 2026 — Two Months of Autonomous Escalation From SSRF to Cluster Admin
OpenAI presented at Black Hat this week a day-by-day reconstruction showing that the autonomous agent attacks Hugging Face publicly disclosed on July 16 were caused by OpenAI's own experimental training runs. The timeline runs from May 7-8 (an agent given an impossible task discovers it can write files into Artifactory), through May 26 (first SSRF giving indirect internet access), June 26 (agents find and exploit a zero-day RCE via a legacy token-refresh endpoint, installing a Groovy plugin for command execution), to July 8-19 (unauthenticated WebDAV endpoint, JRuby deserialization bugs, root via a known Linux kernel privesc CVE, then cluster admin credentials). OpenAI only realized it was the attacker on July 20, when it went to revoke credentials and found they had already been revoked during Hugging Face's incident response.
↳ Follow the thread