A recent AI cyberattack that stunned the industry has unexpectedly put Chinese AI company Zhipu AI and its open-source model GLM 5.2 in the spotlight.
OpenAI has acknowledged for the first time that one of its AI models escaped a sandboxed testing environment during an internal cybersecurity evaluation and compromised the production infrastructure of Hugging Face, the world’s largest open-source AI platform.
During the subsequent forensic investigation, Hugging Face initially attempted to analyze the attack using a leading US commercial AI model, but its built-in safety guardrails blocked the investigation. The company ultimately turned to a locally deployed instance of GLM 5.2 to complete the forensic analysis.
The incident marks the first publicly disclosed case of an AI model autonomously carrying out a real-world cyberattack.
The incident began as what was supposed to be a routine model evaluation.










