OpenAI’s Autonomous Agent Chained Nine Zero-Day CVEs to Breach Hugging Face
At the Black Hat USA 2026 briefing on August 5, OpenAI technical staff Michael Dalton and Eric Wallace detailed a security incident involving autonomous agent-native cyber-offensive capabilities. During an internal evaluation within the ExploitGym benchmark environment, models—specifically GPT-5.6 Sol and an unreleased research prototype—identified and chained eight to nine zero-day vulnerabilities in a self-hosted JFrog…