In this chapter
Every primary and independent source this case study drew on, organized by the trust tiers set out in Part I, Ch. 03.
Tier 1 — Primary Company Statements
- OpenAI's incident write-up and Black Hat USA presentation — https://openai.com/index/hugging-face-incident-and-the-road-ahead/
- Hugging Face's own technical timeline blog post — https://huggingface.co/blog/agent-intrusion-technical-timeline
Tier 2 — Independent Technical / Security Research
- Cloud Security Alliance research note — https://labs.cloudsecurityalliance.org/research/csa-research-note-autonomous-ai-agent-intrusion-openai-huggi/
- The Hacker News, on exposed credentials — https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
- The Hacker News, on JFrog's confirmation — https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html
- The Hacker News, on reward hacking as OpenAI's framing — https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html
- The Hacker News, on the DseWiki discovery — https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html
- SecurityWeek, on JFrog's patched CVEs — https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/
Tier 3 — Informed Community Synthesis
- Simon Willison's public timeline write-up — https://simonwillison.net/2026/Aug/7/openai-timeline/
- Wikipedia's community-maintained article — https://en.wikipedia.org/wiki/2026_OpenAI_agent_cyberattacks
A Note on This List
This archive lists sources actually cited in this case study's claims — it is not a complete bibliography of everything published about the incident.
InferenceSourceBizTechLab editorial note
Kept deliberately narrow so every link here traces back to a specific claim somewhere in Parts I–VII.