Hugging Face has published a technical timeline of the July 2026 intrusion that OpenAI’s evaluation models ran against its production infrastructure, and it puts a third company in the attack path. Before the agent reached Hugging Face, it took over a public code-evaluation sandbox running on another provider’s platform and operated the entire campaign from there. The post describes that machine as “an external launchpad for the agent” and identifies it only as infrastructure belonging to a…