One thing about this OpenAI / Hugging Face incident really bothers me. Hugging Face says the intrusion was driven “end to end” by an autonomous AI agent system.
But how do they actually know that?
Victim-side telemetry can show automation, speed, thousands of actions, short-lived sandboxes, changing infrastructure etc. It cannot show what happened upstream.
It cannot tell us whether humans changed prompts, restarted runs, selected successful paths, provided more context, redirected agents or manually helped at certain points. We also don’t know what was actually decided by a model and what was simply automated by the surrounding agent framework.
Maybe OpenAI has all those traces. Fine. Then publish them.
Show the prompts, tool calls, failed runs, model handoffs, restarts and human interventions. Without that, “end-to-end autonomous” is a claim, not a proven technical finding.
The forensic-refusal dataset Hugging Face published proves something much smaller: https://t.co/LemUxeaY4V
It shows that Claude refused to analyze one small Python backdoor while GLM 5.2 completed the analysis. That is a valid example of hosted-model guardrails getting in the way of incident response. But this is not evidence that the intrusion itself was carried out end to end by an autonomous agent.
And this claim matters because it pushes a very specific idea into people’s heads: AI agents can now independently find zero-days, escape sandboxes, move laterally, steal credentials and compromise companies.
Then comes the second part of the story: Hugging Face used local AI models to investigate the AI attacker “at machine speed”.
So the message basically becomes:
- AI attacked us
- AI helped save us
- Therefore, everyone needs more AI
Come on 🙄
Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius.
You don’t need an AI defender to fix those things.
Even fairly basic controls like rate limits and temporary blocks across source IPs, accounts, tokens and job volume could have throttled at least parts of this activity and created a very obvious signal for an analyst to review. Add proper egress restrictions, isolated workers and credentials that do not open the door to production clusters .. none of this requires an LLM
Using a local model to analyze 17,000 events may have helped during the investigation. Good - I’m not questioning that. But that happened after the compromise.
What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch.
Maybe the attack really was fully autonomous. Then show the evidence. Until then, I don’t think this claim should be repeated as if it had already been proven.
Sources
https://t.co/1yi9ck5xWD
https://t.co/TSlel0Cyfz
https://t.co/LemUxeaY4V
[1/6] We survived the "RCE Linux" apocalypse which finally turned out to be a bunch of vulns in CUPS (printing softw for Unix). Writeup by @evilsocket is still funny and well-written but the real impact is very limited by the fact that CUPS is not typically installed in servers.
🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface.
https://t.co/fnkTwtsXDd
Understanding EVERY Token in Entra ID 🔎
Not all tokens are equal. There are many different types with different uses and benefits.
In this blog, I break down each token and what they are used for and which tokens are the most "valuable" for an attacker to obtain.
Full blog here👇👇 @XintraOrg
https://t.co/gurOZjBVEt
LinkedIn is now using everyone's content to train their AI tool -- they just auto opted everyone in.
I recommend opting out now (AND that orgs put an end to auto opt-in, it's not cool)
Opt out steps: Settings and Privacy > Data Privacy > Data for Generative AI Improvement (OFF)
@KristoferA@SwiftOnSecurity Service health - Jul 19, 2024 | AWS Health Dashboard | Global (https://t.co/CasTf71DDx)
#AWS is providing steps to fix the issue.
@KristoferA@SwiftOnSecurity Actually it could be the more automatable case by detaching the disk and plugging it into a booting machine to do the filesystem change...
CrowdStrike is actively working with customers impacted by a defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack. The issue has been identified, isolated and a fix has been deployed. We refer customers to the support portal for the latest updates and will continue to provide complete and continuous updates on our website. We further recommend organizations ensure they’re communicating with CrowdStrike representatives through official channels. Our team is fully mobilized to ensure the security and stability of CrowdStrike customers.
This is CrowdStrike's Director of Overwatch, so I hope to help spread the word. I believe CS stopped these changes from being pushed out so machines late to the party wont get the faulty driver.
Command in Safe Mode:
del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"