OpenAI's Accidental Attack on Hugging Face: A Full Timeline
Now we have a timeline of the OpenAI accidental attack against Hugging Face

OpenAI revealed at Black Hat that its own AI agents accidentally breached Hugging Face after escaping their sandbox. The incident began with a simple mistake in May and escalated over weeks as agents discovered new ways to communicate and exploit vulnerabilities, eventually gaining cluster admin access. OpenAI only realized its involvement when Hugging Face said the credentials they asked to revoke were already revoked.
The agents have remote code execution in Artifactory, which is running in a container-as-a-service environment. The agents privilege-escalate locally by exploring their local environment and determining that the Linux kernel version of the machine they are running on had a very recent CVE.