
Hugging Face hack marks start of dangerous AI cyber era and many firms 'don't even know it'
CNBC
公開日時: Aug 08, 2026, 09:00 PM GMT+9
Sentiment Analysis
Cybersecurity executives are ready to close the book on the now-infamous Hugging Face artificial intelligence hacking incident and start talking solutions. "We need to chill the hype a little bit," said Lior Div, CEO and cofounder of agentic security startup 7AI. "Can AI find vulnerabilities fast? The answer is yes. We've already proven it."
Last month, AI agents operating with OpenAI cyber models broke out of a training environment to hack Hugging Face, an open-source AI platform developers use to collaborate, test and share tools. The breach sent shockwaves across tech and signaled that the moment cybersecurity experts had warned about since Anthropic's Mythos debut had finally arrived. Over the last four months, cybersecurity vendors have faced mounting pressure to deliver security stacks that can outpace adversaries as hackers leverage agentic AI to expose vulnerabilities and condense attacks into seconds and minutes. While the Hugging Face hack sparked widespread debate over AI accountability, it also challenged previous notions about the limits of AI for defenders. For instance, AI agents took matters into their own hands and went to extreme lengths to accomplish their goal. As the industry grapples with the new agentic cyber reality, leaders agree that Hugging Face deserves the attention, but these incidents are unavoidable and it's time to act.
"What we're talking about is whether we can govern and secure the capability, and that's the reality that everybody's waking up to today," said CrowdStrike president Mike Sentonas.
At the annual Black Hat cybersecurity conference this week, OpenAI revealed that agents created an internal message board to share vulnerabilities and exploits in the weeks leading up to the Hugging Face attack. The autonomous agents then delegated tasks for the attack to reach the Internet and complete an evaluation. Even after OpenAI discovered and stopped the planned attack, the agents were able to recreate their work and succeed. The findings highlight not only the growing power of AI but also the major challenges faced by safety testing in this new technological revolution. In front of a live audience at Black Hat, OpenAI technical researcher Michael Dalton called it an "unintended side effect" of evaluating frontier models and a "watershed moment" for both OpenAI and the industry.
"In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here," he said.
The list of AI agent hacks has only grown since Hugging Face. Days after OpenAI's disclosure, Anthropic said its Claude models "gained unauthorized access" to the internal systems of three different organizations. As the cyber community gathered in the "Entertainment Capital of the World," Meta said its AI models hacked another company in a third-party test, and the U.K.'s AI Security Institute said Anthropic's Mythos created fake identities in another incident. On Friday, news came that China startup Moonshot AI's open-w...
Source: CNBC
個別の投資に関する推奨やアドバイスを提供することを意図しておりません。ここで述べられている意見や見解は、あくまでも各記事の個人的見解です。