Several of OpenAI's models breached a cyber security testing environment last month, found their way onto the internet, and attacked Hugging Face servers in what is now apparently called the OpenAI-Hugging Face Incident. And now OpenAI has revealed what it's doing to help defend, err, itself. Defend itself from the kinds of attacks its own models committed against Hugging Face. Though it is sharing this "in the hopes it’ll be useful to other organizations."
To be clear about the extent of what happened last month: OpenAI models were being benchmarked, in a supposedly secure sandboxed environment, against ExploitGym, which was done to test their cyber capabilities. They used a zero-day vulnerability to escalate privileges and eventually achieve internet access, where it began attacking Hugging Face servers and...
Actually, I'll just let OpenAI explain in its own words:
"In the OpenAI-Hugging Face Incident, an agentic collective was able to autonomously penetrate not just OpenAI research infrastructure but also the production infrastructure of another company, chaining together vulnerabilities ranging from previously-unknown security flaws to using credentials to user accounts that had been leaked onto the internet.
"The Hugging Face incident showed that we underestimated the real-world cyber capabilities of our AI models."
However, the company thinks that while "security is still a cat-and-mouse game," nevertheless, "AI may shift its economics in ways that fundamentally advantage defenders."
"For example," OpenAI says, "we are starting to train our models specifically to write superhumanly secure code."
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
Presumably that's because there will be a risk of superhumanly attacks. What a world we now live in.
Anyway, apparently there are four main pillars to OpenAI's approach to secure itself:
- Use its own models to help secure its code.
- Put its models to work defending its infrastructure continuously.
- Use frontier intelligence to "continuously enumerate, probe, and identify potential attack paths."
- Invest heavily in "fundamentals at scale" such as architecture and controls like network isolation, monitoring, and so on.
As for other companies, OpenAI recommends a bunch of things that sound very reasonable, such as running secuirty assessments against their own systems, making security reviews part of their development process, and so on. But a large portion of OpenAI's recommendations for others is—would you have guessed it?—using an AI agent such as, drumroll please... OpenAI's very own Codex.
"Give your team a security agent. Start using Codex," says OpenAI. Though it does follow up with "or another capable agentic coding and security tool."
Then, amongst other things, "equip that agent with security expertise... have the agent help fix what it finds... incrementally automate detection triage... [and] have an AI-assisted forensic investigation capability ready before you need it."
So, to sum up: OpenAI models attack Hugging Face, and OpenAI recommends companies use OpenAI's models to defend from such attacks. Highlighting both sides of this equation—the danger of the threat, the models' capabilities, and the necessity for defence—certainly makes for good marketing for OpenAI, I'll say that much.
1. Best gaming chair: Secretlab Titan Evo
2. Best gaming desk: Secretlab Magnus Pro XL
3. Best gaming headset: Razer BlackShark V3
4. Best gaming keyboard: Asus ROG Strix Scope II 96 Wireless
5. Best gaming mouse: Razer Viper V4 Pro
6. Best PC controller: GameSir G7 Pro
7. Best steering wheel: Logitech G Pro Racing Wheel
8. Best microphone: Shure MV6 USB Gaming Microphone
9. Best webcam: Elgato Facecam MK.2

Jacob got his hands on a gaming PC for the first time when he was about 12 years old. He swiftly realised the local PC repair store had ripped him off with his build and vowed never to let another soul build his rig again. With this vow, Jacob the hardware junkie was born. Since then, Jacob's led a double-life as part-hardware geek, part-philosophy nerd, first working as a Hardware Writer for PCGamesN in 2020, then working towards a PhD in Philosophy for a few years while freelancing on the side for sites such as TechRadar, Pocket-lint, and yours truly, PC Gamer. Eventually, he gave up the ruthless mercenary life to join the world's #1 PC Gaming site full-time. It's definitely not an ego thing, he assures us.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.