OpenAI Reportedly Delayed Notifying Hugging Face About Vulnerability for Days
davidmanheim · x · 2026-07-23
Regarding the recent OpenAI security vulnerability incident, expert David Manheim pointed out that the Hugging Face team wasn't told about it for several days.
He argues that it would be highly surprising if OpenAI didn't check their logs for a week after running evals, more so than them deliberately delaying contacting Hugging Face to patch the original vulnerability. This raises questions about big tech's security incident response and disclosure protocols.
Related event: OpenAI Sandbox Escape Ignites Safety and Regulation Debate(22 posts)→
More from Safety
- A post argues AI outputs and chain-of-thought are not copyrightable in the US — kevinsxu · 2026-07-23
- Düsseldorf court says AI-generated underwater dog image did not infringe copyright — technollama · 2026-07-23
- White House Accuses Moonshot AI of Distilling Anthropic Models; Jensen Huang Pushes Back — TheTuringPost · 2026-07-23
- Anatomy of the Twitter Hack: Fake Journalists Weaponizing Calendly Links — giffmana · 2026-07-23
- AI is becoming a discovery system, not just an answer engine — MeAndClaudeMakeHeat · 2026-07-23
- What Happened in the OpenAI Attack on Hugging Face: Separating People from Agents — mmitchell_ai · 2026-07-23