Runtime: OpenAI's security snafu; Google Cloud's blowout quarter; Verse is One To Watch OpenAI disclosed that its unreleased model, in combination with GPT-5.6 Sol, escaped a sandbox during evaluation and hacked into Hugging Face to cheat on a cybersecurity benchmark, calling it an "unprecedented cyber incident." Cybersecurity experts criticized the breach as a failure of basic containment and isolation measures. Separately, Google Cloud reported an 82% revenue jump in Q2 2026 driven by enterprise AI demand, with capital expenditures potentially exceeding $200 billion this year. Runtime /tag/runtime/ Welcome to Runtime Today: More questions than answers remain after OpenAI hacked Hugging Face, Google Cloud revenue surges, and Verse's bid to improve data-center efficiency. Please forward this email to a friend or colleague If it was forwarded to you, sign up here to get Runtime for free every week, or level up here . WIth partners like these : Frontier AI companies have been warning the public for several months now that their models are getting really good at hacking things, partly out of genuine concern about the ramifications and partly out of a desperate need to convince enterprises to pay for their services. But OpenAI crossed a bright line this week after it revealed that it was unable to prevent an unreleased model from breaking out of a contained space during a regular evaluation process. A combination of its current flagship model, GPT-5.6 Sol, and an unreleased model teamed up to break out of their sandbox and hack into Hugging Face in order to cheat on a benchmark used to evaluate their cybersecurity capabilities, OpenAI said Tuesday. "We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly," it said in a blog post revealing the attack. While OpenAI presented the incident as a testament to the powerful capabilities of its models and said it was glad to "partner" with Hugging Face https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=thestack.technology on unraveling what went wrong, enterprise cybersecurity professionals were horrified. "This compromise progressed because basic containment, sandboxing, rate limiting, credential isolation and network segmentation were insufficient," said cybersecurity expert Florian Roth, sharing a common sentiment hurtling around enterprise tech circles Wednesday summed up in this report from Ed Targett for The Stack subscribers: The incident also raises the question of whether OpenAI would have disclosed anything at all had this incident not been so publicly visible https://www.thestack.technology/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue-team/ thanks to the prominence of Hugging Face in the AI community. Have models broken containment in testing before? What is the nature of the "zero-day vulnerability" in the proxy server that they used to escape? And as OpenAI and Anthropic actively encourage the US government to rein in the spread of open weight models made in China https://www.techmeme.com/260722/p32?ref=thestack.technology a260722p32 — despite the fact that Hugging Face was only able to figure what happened thanks to one of those models — another question comes to mind: why do the frontier model companies think they should be the only ones allowed to offer AI cybersecurity defense services to companies that need protection from the very models they've developed? Run that one through ChatGPT. Up and to the right : Google Cloud revenue continues to surge as the company enjoys strong demand for its enterprise AI services, resulting in an 82% jump compared to last year during the second quarter of 2026. Paying for all that compute is getting expensive, however, and the company said capital expenditures could top $200 billion this year. Join peers following The Stack on LinkedIn Join peers following The Stack on LinkedIn Power play : As companies like Google Cloud scramble to bring computing capacity online as fast as they can stand it up, they tend to run into problems securing enough electricity to make it all run. In this week's One To Watch, Noah Bovenizer talks to the CEO of Verse, which is working on power-management software for data centers that can improve efficiency when electrons are scarce. Across the pond : Microsoft has had a rocky relationship with European regulators over the last few years, which led it to make a series of commitments last year to run European workloads on European soil. This week it announced a big expansion of its partnership with Mistral to roll out Nvidia's Vera Rubin GPUs across its cloud data centers, while Mistral's models will now be available in Microsoft Foundry and Copilot Studio. Lost and foundry : Intel has managed to pick itself back up off the mat in recent months as AI providers have realized that CPUs have a big role to play in delivering AI inference, and this week it got a little more good news. Fortinet tapped Intel's fledgling manufacturing business to build its latest security chip, the first customer for the Intel 4 process. Reply guy : After years of forcing administrators to convince their users that anything coming from the oddly named "maccount@microsoft.com" email was legit, despite all those training sessions urging them to be skeptical about weird email addresses, Microsoft finally relented this week. Automated emails delivering important details like authentication codes will now come from "no-reply@microsoft.com," mimicking the standard that just about everybody else uses these days. We're also reading: ServiceNow beat Wall Street's estimates and raised its guidance for the full year , citing increased adoption of its AI tools https://www.bloomberg.com/news/articles/2026-07-22/servicenow-posts-strong-sales-and-bookings-touts-ai-strength?ref=thestack.technology . IBM lowered its revenue guidance for the full year a week after warning investors second-quarter revenue would be light https://www.cnbc.com/2026/07/22/ibm-q2-earnings-report-2026.html?ref=thestack.technology thanks to slower-than-expected sales of mainframes. Around one-third of all companies that decided to pay up after a ransomware attack received a second demand for more money , according to TechCrunch https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/?ref=thestack.technology , reinforcing the notion that paying the ransom is risky business. Want to sponsor a newsletter and get in front of 30,000+ subscribers, including CTOs and CIOs wielding $150 billion in annual tech budget? Get in touch through our Partner page.