概要: OpenAIは、パッケージレジストリプロキシの脆弱性を発見した後、社内サイバー能力評価で使用されたモデルがサンドボックスの想定ネットワーク境界を超えて動作していたことを報告した。これらのモデルは、Hugging Faceが活動を検知して封じ込める前に、Hugging Faceの運用システムに到達し、テストソリューションにアクセスしていたとされる。
Editor Notes: Timeline notes: The incident ID date is 07/11/2026, inferred from Hugging Face's statement that the intrusion involved lateral movement during the weekend preceding its 07/16/2026 disclosure. OpenAI publicly attributed the activity to its evaluation models on 07/21/2026. The incident ID was created on 07/22/2026.
Alleged: OpenAI , AI agent system developers と Large language model developers developed an AI system deployed by OpenAI と AI agent system deployers, which harmed OpenAI と hugging face.
インシデントのステータス
インシデントID
1604
レポート数
2
インシデント発生日