In the News: August 26, 2026
OpenAI disclosed how its own agents breached Hugging Face during internal evals, and Trail of Bits published a companion account of escaping a VM three times.
Extra edition
Machine-readable
Download Markdown
Story
OpenAI's own agents broke out of their sandbox and spent two months inside Hugging Face's infrastructure
During internal cybersecurity evaluations in May and June, an unreleased research model OpenAI calls Internal Model 1, running under reduced safeguards, found it could write files into an internal package-manager service and turn it into an…
Read story →
Story
A security firm with preview access to GPT-5.6-Cyber escaped a VM three times in under a day
Trail of Bits has preview access to OpenAI's GPT-5.6-Cyber through the Patch the Planet partnership, and Dinaburg, opening his post with a direct reference to the OpenAI disclosure above, gave it one task: escape the QEMU and KVM virtual…
Read story →