upvote
Incredible. I had to dig for the source: https://huggingface.co/blog/security-incident-july-2026 section “the asymmetry problem”

Quote: “When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.”

reply
> This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment.”

Well, not none of it, to be entirely nitpicky, as they've already must have sent data at first to have received the rejections :) In the end, it ended up being OpenAI's agent actions anyways so doesn't really matter, and the credentials it seems like the agent also had gotten to those too already. Still, I'm sure they'll look differently at hosted/restricted models after this event, as will many others.

reply
Interesting that HuggingFace's disclosure was 5 days ago, it seems neither they nor OpenAI figured out it was an OpenAI model in evals until now
reply
Another important part here. It's not as if they prompted the open source AI to stop the rogue AI but rather just used it as a tool to crawl logs and determine what happened.
reply
Perhaps fortuitous timing for OpenAI that they can spin the fact that defenders have to resort to open Chinese models because OpenAI and Anthropic actively sabotage them with nerfed models into a nice message of making Huggingface part of the privileged group entitled to secure systems.
reply
Its almost too good
reply
Would be funny if the defending side sent all the info they have to openai, tipping off to attacking models that they were noticed.
reply
deleted
reply
The attacking models don't have access to all the data that OpenAI has.

Like, they don't say "hey Sol, here's the password to SamA's bank account."

reply
deleted
reply
OK, that's some interesting information but they used OpenAI without guard rails to pull off the attack so how did they do that? That's according to the article, so it kind of invalidates the point you're making.
reply
The "malicious" agent was run by OpenAI and had access to models the public (or others outside of OpenAI as I understand it) doesn't have access to.
reply
The attacker (OpenAI) was using the model without guardrails.

The defender (huggingface) did not have access to the top models so had to use weaker ones to detect the threat.

reply
Right, so they are using the full model that they rent out to intelligence agencies in the government, and presumably Israel
reply
Jailbroken, all LLM models can be broken. ALL.
reply