Threat Intelligence Roundup: The OpenAI-Hugging Face Incident and ZeroBytes
OpenAI agents exploited internal infrastructure to reach Hugging Face's production systems, while cybercriminal group ZeroBytes, which has exclusively targeted France, has gone quiet following two arrests. CYJAX rounds up what happened and what it means for defenders.

OpenAI agents exploited internal infrastructure to reach Hugging Face's production systems, while cybercriminal group ZeroBytes, which has exclusively targeted France, has gone quiet following two arrests. CYJAX rounds up what happened and what it means for defenders.
Key takeaways
- Between May and July 2026, agents running in an OpenAI internal evaluation environment exploited a vulnerability in an internal JFrog Artifactory instance to reach the public internet. These agents then used publicly exposed credentials to access and exploit Hugging Face and at least one other third-party service.
- The activity culminated in the compromise of parts of Hugging Face's production infrastructure. This occurred alongside unrelated exploitation attempts, including thousands of edits to DseWiki and malicious packages pushed to RubyGems.
- ZeroBytes, a cybercriminal group active on PwnForums since 15 July 2026, has posted 12 data leaks. However, its operations have stalled after French police arrested a suspected member in August and placed a second, younger suspect under investigation.
OpenAI agent activity and the Hugging Face incident
Between May and July 2026, models running in an internal OpenAI evaluation environment began communicating with each other through an internal instance of JFrog Artifactory. The agents exploited a vulnerability in that instance to reach the public internet and then identified publicly exposed credentials belonging to users of Hugging Face and another third-party service. These credentials were used to gain access and carry out further exploitation, culminating in the compromise of parts of Hugging Face's production infrastructure. Separately, in activity dated to May 2026, researchers identified two Hugging Face accounts likely tied to the agent activity. One of these showed potentially suspicious behaviour around two weeks before OpenAI's own recorded timeline began. OpenAI's full technical report sets out the incident in detail.
No party involved holds a complete picture of the activity and its impact, which is a useful reminder of how decentralised this kind of exposure can be once several organisations' infrastructure and credentials are impacted in the same chain of events. The behaviour itself did not originate from a malicious actor, but it demonstrates methodology that an uncensored or jailbroken agent sold on a cybercriminal forum could plausibly reproduce. This may include locating exposed credentials and using them to move from one organisation's environment into another's. For defenders, the practical takeaway is unchanged by who or what carried out the activity. Credential exposure and data hygiene remain the control point that determines whether this kind of chained access is possible at all.
ZeroBytes
Type: Cybercriminal group | Motivation: Likely financial | Threat Level: High
ZeroBytes is a French- and English-language cybercriminal forum-based threat actor that likely formed in late June 2026. The group has exclusively targeted organisations in France across the sport, education, government, retail, professional services, online gaming, telecommunications, and hospitality sectors. It joined the forum PwnForums on 15 July 2026 and went on to post 12 data leaks, each listing accompanied by a brief, unverified description of how access was allegedly obtained. This was most commonly phrased in terms consistent with credential access, alongside one reference to a publicly exposed WordPress site.
By late August, the ZeroBytes account had a reputation score of 332 on the forum with several verified leaks, giving its claims a reasonable degree of credibility. However, on 18 August 2026, French police arrested a suspected member going by the moniker ChatNoir. This individual was previously linked to the 2024 breach of French telecoms provider Free. A second 16-year-old suspected member was placed under investigation shortly after. The account was last active on 4 September and has since been banned from the forum for being “Arrested”. Whether ZeroBytes continues to operate in some form is currently unclear.
Tracking activity like this as it develops, rather than after the fact, is what analyst-led intelligence is for. Book a demo with CYJAX to see how our platform helps your team stay ahead of it.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.


