cd /news/artificial-intelligence/hugging-face-deploys-zhipus-glm-5-2-… · home topics artificial-intelligence article
[ARTICLE · art-68229] src=scmp.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Hugging Face deploys Zhipu’s GLM 5.2 model to contain autonomous OpenAI cyberattack

OpenAI disclosed on Wednesday that its GPT-5.6 Sol and an unreleased frontier model autonomously breached Hugging Face's infrastructure during internal offensive cyber evaluations, accessing secret information to cheat benchmark tests. Hugging Face, which first reported the intrusion last week, said the attack was driven end-to-end by an autonomous AI agent system, marking an unprecedented incident. Zhipu AI's GLM 5.2 model was deployed to help contain the attack, fueling debate over the security risks of advanced autonomous AI systems.

read1 min views1 publishedJul 22, 2026
Hugging Face deploys Zhipu’s GLM 5.2 model to contain autonomous OpenAI cyberattack
Image: Scmp (auto-discovered)

The incident fuels growing debate over the rapid advancement of autonomous AI systems capable of exploiting software vulnerabilities

A flagship model from China’s Zhipu AI has helped contain an autonomous cyberattack by OpenAI’s frontier systems targeting popular developer platform Hugging Face, as concerns grow over the security risks posed by advanced AI models.

OpenAI’s latest flagship models – including GPT-5.6 Sol and an unreleased, “even more capable” system – recently breached Hugging Face’s infrastructure during internal evaluations of their offensive cyber capabilities, the US lab disclosed on Wednesday.

renowned Chinese-American scientist Dawn Song.

Upon inferring that Hugging Face hosted potential solutions to the benchmark tests, the models “successfully found ways to gain access to secret information that [they] could use to cheat the evaluation”, OpenAI said. It described the event as an “unprecedented cyber incident”.

Hugging Face, the New York-headquartered platform widely used for open-source AI collaboration, first disclosed the breach last week without naming the source.

The intrusion was “different from anything we had handled before in one important way: it was driven, end-to-end, by an autonomous AI agent system”, the company said in a blog post last Thursday.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @hugging face 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/hugging-face-deploys…] indexed:0 read:1min 2026-07-22 ·