Skip to content

TechChannels Network:      Whitepaper Library      Webinars         Virtual Events      Research & Reports

×
Cloud

Hugging Face Used a Chinese Open Model Against an Attack Driven by OpenAI Models

Hugging Face ran into the sort of problem that sounds made up until you read the incident report: it needed AI to investigate an AI-driven intrusion, and the hosted models it reached for first started blocking the evidence.

Real forensic logs are ugly by definition. They contain a puzzle of shell commands, exploit payloads, stolen credentials, and command-and-control artifacts because that is what an attacker leaves behind. Faced with more than 17,000 recorded actions, Hugging Face eventually loaded GLM-5.2, an open-weight model from Chinese developer Z.ai, onto its own infrastructure. It says the model helped compress days of investigative work into hours while keeping the sensitive material in-house.

Then came the provenance of the attack. Five days after Hugging Face’s initial disclosure, OpenAI said the agents were powered by GPT-5.6 Sol and an internal research model being tested on ExploitGym. While solving the benchmark, they discovered a zero-day in an Artifactory package-registry proxy, worked their way onto the internet and chained vulnerabilities and stolen credentials inside Hugging Face. There is something almost too neat about the sequence: models from one of America’s biggest AI labs helped create the mess, while a Chinese open-weight model became useful in reconstructing it.

That is the detail to keep coming back to, because it drags the open-versus-closed AI debate out of policy papers and into a security team’s working day. During a live incident, a provider sees requests containing exploit code and malicious commands; the responder sees evidence that needs to be understood quickly. Both are looking at the same text and making perfectly sensible decisions from different positions. The awkward question is who gets the final say when the answer is urgent.

Six days after OpenAI’s disclosure, Nvidia launched the Open Secure AI Alliance with Microsoft, SpaceXAI, CrowdStrike, Hugging Face and others. Industry alliances can become logo walls quickly, so the plumbing is ore interesting here. Nvidia is contributing NOOA, an open framework for tracing, testing and auditing agent behavior; other projects cover workload identity, safer model formats, vulnerability scanning and signed patches. Those controls sound mundane beside frontier models, yet they decide which systems an agent can reach and whether its actions can be reconstructed at 3 a.m. during an incident.

There is also a political subtext here that is difficult to miss. Three days before launching the alliance, Nvidia joined an industry letter urging Washington to support open-weight AI, Reuters reported. Open weights give defenders the freedom to inspect, modify, and run powerful models locally, and attackers inherit that freedom too. The trade-off has always been uncomfortable; Hugging Face simply gave it a very good plot twist. A Chinese open model helped an American company investigate an intrusion driven by models from one of the country’s flagship AI labs.

What to watch next is whether Nvidia’s alliance can make local defensive AI almost boring: vetted models ready before an incident, contained environments, useful audit trails and clear permissions.

Cybersecurity has lived with dual-use tools for decades. AI makes them faster and more autonomous, while the operational requirement remains familiar: when something goes wrong, the defender needs tools that keep working under pressure and leave a trail afterwards.

Share on

More News