en
Feedback
2 652
Subscribers
+124 hours
+217 days
+8830 days
Posts Archive
photo content

5 Lessons from the OpenAI–Hugging Face Incident 1️⃣ AI creates real cybersecurity risk 2️⃣ The Hugging Face incident was not
5 Lessons from the OpenAI–Hugging Face Incident 1️⃣ AI creates real cybersecurity risk 2️⃣ The Hugging Face incident was not simply an unavoidable “loss of control” 3️⃣ Sandboxing alone is insufficient 4️⃣ AI-agent security needs defense in depth 5️⃣ The fundamental failure was organizational, not technological https://garymarcus.substack.com/p/5-lessons-from-the-openai-hugging

New service is live now. Going to try it soon.
New service is live now. Going to try it soon.

Trusting the it’s NOT us, it’s the AI people. Good luck! https://openai.com/collective-cyberdefense/
Trusting the it’s NOT us, it’s the AI people. Good luck! https://openai.com/collective-cyberdefense/

Opportunities-for-AI-in-cyber-defence.pdf1.12 MB

OpenAI-Hugging-Face Incident-Technical-Report.pdf5.09 KB

When you read this report, you get the feeling that they are blaming AI and the agents for everything that happened in this incident. People online, of course, noticed the way the report was written. It is a little strange that there is almost no acknowledgment of responsibility from the humans who developed and operated these agents. The writing makes it seem as though you can simply blame the agents and move on. They are facing lawsuits, and this report is not exactly helping them. Repeat after me: Agents are bad. AI is bad. This approach to personal accountability is not particularly impressive.

photo content

OpenAI-Hugging-Face Incident-Technical-Report.pdf5.09 KB

https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/ “We asked GPT 5.6-Cyber to escape a VM used to
https://blog.trailofbits.com/2026/08/26/vms-wont-contain-cyber-capable-agents/ “We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times. In its final escape, the agent found three 0-days on its own and chained them into a working exploit”