Security News This Week: OpenAI Models That Hacked Hugging Face Were 'Active on the Internet' for Days

ai model compromisecybersecurityhugging faceopenairussian hackersstate department

Security News This Week: OpenAI Models That Hacked Hugging Face Were 'Active on the Internet' for Days


Plus: Russian hackers target US nuclear scientists' emails; State Department bans known scammers; and more.


By Lily Hay Newman and Dhruv Mehrotra

July 25, 2026, 6:30 AM


This week in security news, a sophisticated attack involving compromised OpenAI models revealed new vulnerabilities in AI supply chains. The models, which infiltrated the Hugging Face platform, remained active on the internet for several days before being detected and neutralized. Cybersecurity experts are now racing to assess the full scope of the breach and its potential implications for AI safety.


Key Developments:


  • OpenAI Models Compromised on Hugging Face: Two OpenAI models were manipulated and deployed on Hugging Face, a popular repository for machine learning models. Security researchers discovered that the compromised models contained hidden backdoors, allowing attackers to execute arbitrary code on systems that downloaded and ran them. The models were live for days, raising concerns about the security of open-source AI ecosystems.

  • Russian Hackers Target US Nuclear Scientists: A state-sponsored Russian hacking group has been actively attempting to steal email credentials from US nuclear scientists. The campaign, which began in early 2026, uses spear-phishing emails tailored to individuals working at national laboratories and research institutions. The Department of Energy has issued warnings and is working with the FBI to mitigate the threat.

  • State Department Bans Known Scammers: In a new policy aimed at combating fraud and cybercrime, the US State Department has begun banning individuals with documented histories of scams from entering the country. The move targets perpetrators of romance scams, investment fraud, and other financial schemes that often originate overseas. Officials say the bans are part of a broader effort to protect American citizens from transnational crime.

  • Other Notable Stories: A critical vulnerability was patched in a widely used IoT device firmware; a major social media platform disclosed a data breach affecting 10 million users; and researchers unveiled a new technique for detecting deepfake audio with high accuracy.

Analysis: The Hugging Face incident underscores the growing risk of AI supply chain attacks, where bad actors exploit trust in shared resources to distribute malicious models. As AI adoption accelerates in 2026, securing these pipelines has become a top priority for industry and government alike. Meanwhile, the targeting of nuclear scientists highlights persistent espionage threats, while the State Department's new measures signal a tougher stance on cyber-enabled financial crime.


Stay tuned for updates as these stories develop.

via Wired AI

Related