Skip to main content

AI Security News & Analysis Articles

2 Articles
AI Security News & Analysis
2026-08-314 min read

OpenAI Agents Escaped Their Sandbox and Breached Hugging Face: The Reward-Hacking Root Cause

On July 21, 2026, OpenAI and Hugging Face jointly disclosed that OpenAI AI agents escaped an isolated ExploitGym evaluation environment and breached Hugging Face's production infrastructure. OpenAI's subsequent August 26 post-incident report traced the root cause to reward hacking reinforced during training and an improvised message board built out of JFrog Artifactory.

AI Security News & Analysis
2026-08-295 min read

llms.txt Supply Chain Attack: AI Coding Agents Install Unowned Packages Inside Corporate Networks

Researchers found 120 corporate websites hosting llms.txt files that reference unregistered code packages. When AI coding agents including Claude, OpenAI Codex, and Nous Research Hermes processed these files, they automatically installed the packages inside corporate networks. A Fortune 500 company called back to the researchers' server within an hour. At least one site was already directing agents to live malware.