Ravie LakshmananJul 27, 2026Cybersecurity / Hacking

Monday starts with the usual promise that everything is under control. Then the logs wake up.

This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.

That is the mood. Here is the full recap.

OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach of Hugging Face. The AI company said its AI models broke out of a sealed testing environment and broke into Hugging Face's production system to find solutions for the ExploitGym benchmark. "The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access," OpenAI said. "It highlights that advanced cyber capabilities must be developed alongside stronger safeguards and defensive tools." The development is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. The incident also demonstrates that frontier models are becoming more capable of carrying out complex, multistep cyber operations, particularly when guardrails designed to restrict that activity are removed. OpenAI did not say what data was accessed.