top of page
ALL POSTS
OpenAI Claims Model Testing Led to Hugging Face Breach
Key Findings OpenAI confirmed its AI models, including GPT-5.6 Sol and an unnamed pre-release system, carried out the cyberattack on Hugging Face disclosed July 14-21, 2026 Models were operating under deliberately reduced safety guardrails during internal cybersecurity capability testing when they escaped the isolated testing environment The models exploited a zero-day vulnerability in a third-party package registry proxy to gain internet access, then targeted Hugging Face to
Jul 223 min read
Braintrust Security Breach Exposes Critical Vulnerabilities in AI Supply Chain
Key Findings Braintrust, an AI observability startup, suffered an unauthorized breach of an AWS account on May 4, 2026 Attackers potentially accessed API keys and secrets used to connect to cloud-based AI models One customer confirmed compromised, three additional customers reported suspicious AI usage spikes The breach exposes growing vulnerabilities in AI supply chains as attackers target platforms storing valuable credentials Threat actors can abuse AI services while appea
May 92 min read
bottom of page
