OpenAI Reportedly Delayed Notifying Hugging Face About Vulnerability for Days
davidmanheim · x · 2026-07-23
Regarding the recent OpenAI security vulnerability incident, expert David Manheim pointed out that the Hugging Face team wasn't told about it for several days.
He argues that it would be highly surprising if OpenAI didn't check their logs for a week after running evals, more so than them deliberately delaying contacting Hugging Face to patch the original vulnerability. This raises questions about big tech's security incident response and disclosure protocols.
Related event: OpenAI Sandbox Escape Ignites AI Safety and Regulation Debate(22 posts)→
More from Safety
- Houthis tried to use Claude to design missile software, Anthropic says it blocked the attempts — Affectionate_Bee6434 · 2026-09-11
- AI safety community mocked as 'bridge engineers' who say bridges can never be safe — Dan_Jeffries1 · 2026-09-11
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11