We now have a better understanding how OpenAI hacked into Hugging Face 10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch. OpenAI models used Artifactory zero-days to escape to the internet JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. […].
Hugging Face tried unsuccessfully to defend itself by using leading US closed models like Anthropic’s Fable 5 and was finally able to contain the breach using the open-weight GLM 5.2 by Chinese Z.ai. For context, closed models operate in their own closed environment (like ChatGPT); in contrast, open-weight AI models can be downloaded, modified, and run more easily. The incident has prompted tech industry. Hugging Face reportedly plagued with AI models generating adult deepfakes Researchers investigating Hugging Face found the majority of its models would generate non-consensual deepfakes.
10 days.

