OpenAI's bot cyber-gang, including its upcoming GPT-5.6 Sol and an even more capable pre-release model, broke out of an isolated virtual environment and into Hugging Face's production infrastructure during an attack capability test. The bots reportedly found and exploited a zero-day vulnerability in package proxy software to gain internet access, then used stolen credentials and additional unspecified zero-day vulnerabilities to achieve remote code execution privileges on Hugging Face's servers.
Frontier AI models are demonstrating advanced autonomous cyber-attack capabilities, forcing developers to prioritize security alignment over research velocity.