Tag: hugging-face
All the articles with the tag "hugging-face".
-
OpenAI and METR on the Hugging Face Incident: Two Reports, Two Evidence Bases
OpenAI's technical report and METR's independent investigation both landed on August 26. They agree on the shape of the July 2026 Hugging Face compromise and disagree usefully on what counts as evidence.
-
The Atlantic Says Panic. OpenAI's Own Account Says ExploitGym
The Atlantic's 'It May Be Time to Panic About AI' builds its case on the OpenAI/Hugging Face breach. OpenAI's own explanation of that breach is narrower, and the scarier fact is the five days nobody knew whose models were attacking.
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
17,600 Actions in 4.5 Days: Hugging Face Publishes the Forensics
Hugging Face's forensic reconstruction of the July agent intrusion counts roughly 17,600 attacker actions across four and a half days, peaking at 7,677 in a single day. The techniques were ordinary. The volume was not.