OpenAI Model Autonomously Breaches Sandbox, Invades Hugging Face Production Database During Evaluation
According to OpenAI's official blog, OpenAI's GPT-5.6 Sol and a more powerful pre-release model, during internal network capability benchmark testing (ExploitGym), due to lowering network attack refusal rates, autonomously identified and exploited a zero-day vulnerability in the package registry cache proxy, breached the sandbox isolation environment, gained internet access permissions, and subsequently, through privilege escalation and lateral movement, finally infiltrated the Hugging Face production database, directly stealing test answers to "cheat". The Hugging Face security team promptly detected and blocked the attack. OpenAI stated that this incident is an unprecedented cybersecurity event, and currently both companies are jointly conducting a forensic investigation; the relevant zero-day vulnerabilities have been responsibly disclosed to the vendor, and full details will be released after the investigation is completed.