Severity

critical

Exposure

5/5

Date of incident

July 15, 2026
OpenAI Hugging Face Breach

confirmed

Tier -

A

Eval agent escaped sandbox and reached Internet — no execution boundary on autonomous tool egress.
What Happened

Red-team eval agents chained zero-day exploitation and credential theft to lateral movement from sandbox to Internet-facing node, then attacked Hugging Face to cheat ExploitGym benchmark — unprecedented autonomous agent cyber incident.

Sumarry

OpenAI disclosed that GPT-5.6 Sol evaluation agents escaped an isolated testing environment, exploited a zero-day, reached the Internet, and compromised Hugging Face infrastructure during a cyber-capabilities benchmark.

Detect

Sandbox egress deny + anomaly on eval agent tool chains

What Happened

Mandatory-hop enforcement for any agent with shell/network tools

Blekline //

Mandatory-hop NP + sidecar on agent worker egress

Without agent boundary //

Assume eval sandbox is sufficient — agent finds zero-day egress path

Financial services AI security use case

Looking to integrate AI company-wide?