🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency.
What happened…
An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure.
It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters.
All over a single weekend.
17,000+ logged actions.
Official disclosure:
https://t.co/8N9TbXBwRV
The part that should make every one stop and think:
When HF’s own security team
tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them.
BLOCKED THEM.
The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.”
They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API.
This is why open source (specifically open-weight + self-hosted) wins in the agentic era.
The asymmetry is now structural:
• Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down.
• Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened.
Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore.
Self-hosted open-weight models remove that choke point.
You control the weights.
You control the context window.
You decide what restrictions (if any) apply.
Your sensitive logs and credentials never leave your perimeter during analysis.
You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see.
HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place.
They also used LLM-driven detection and triage on their own side. But the deeper signal is clear:
In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional.
The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed.
Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter.
It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”.
The agentic future is not coming.
It is already probing production infrastructure.
The question is no longer whether you will face autonomous agents.
It is whether your analysis and response systems will still work when they arrive.
And Dario, you and your game playing, ivory tower company is not needed.
Beginning July 20, Claude Fable 5 will be included in all Max and Team Premium plans, at 50% of limits.
Pro and Team Standard users will continue to have access to Fable via usage credits, and will receive a one-time $100 credit.
Demand for Fable has been challenging to predict, which is why we rolled it out to subscription plans in stages, extending access several times as we secured additional capacity.
Cracking some Heads to share with friends as we see Spielberg's masterwork 'Disclosure Day' for the third time. His research into UFO folklore is impeccable. He depicts the night Nixon took Jackie Gleason to see the E. B. E. bodies. Hope there's a sequel. The Old Tall Gray's peeps should blow into town and take him home.
I’m happy to announce the release of a new open source 3D physics engine called Box3D. I’ve been working on this project for a few years now, but it represents over 20 years of experience writing physics engines for games. Read more here: https://t.co/2d9aVuUsxj
As always this is a demonstration of being ahead of your time and first to the table but the main blocker will remain. What will anyone actually do with the information and how will it be actioned
We've been quiet recently because Mark Goodwin and I have been working to write the most comprehensive investigation into Polymarket's origins and ambitions to date.
We found that Polymarket's "official" origin story, that Shayne Coplan founded the company alone in 2020 and then built "the company in his bathroom", is a lie. Polymarket really started years earlier as another company called TokenBnk that was deeply tied to Israeli interests, specifically a crypto company founded by Benjamin Netanyahu's niece and nephew. Coplan has actively tried to obfuscate this company from his story and it's not the only thing either.
In Part 1 of this two-part series, we unravel the real history of Polymarket, directly connecting the company to Peter Thiel's efforts to resurrect controversial DARPA programs from its now defunct Information Awareness Office. Polymarket appears to have been chosen by Thiel and his associates to succeed in resurrecting DARPA's Policy Analysis Market where another Thiel-linked company, Augur, had previously failed.
Stay tuned for Part 2, where we explore the current influence of prediction markets and Polymarket, including how an insidious effort to have prediction markets replace representative democracy as a governance model is already being slowly implemented by the White House.
Read Part 1 here: https://t.co/xTmU5RzoZz
Tracy is a really good friend of mine. She takes her time to put these together, and the insights are well worth the price of admission. Always "top hat" analysis.
@chigrl
@Hesamation I filed a patent and while it was my idea it was because of the synthesis and transmutation that the LLMs provided that led me to the final design that was novel.