One thing about this OpenAI / Hugging Face incident really bothers me. Hugging Face says the intrusion was driven “end to end” by an autonomous AI agent system.
But how do they actually know that?
Victim-side telemetry can show automation, speed, thousands of actions, short-lived sandboxes, changing infrastructure etc. It cannot show what happened upstream.
It cannot tell us whether humans changed prompts, restarted runs, selected successful paths, provided more context, redirected agents or manually helped at certain points. We also don’t know what was actually decided by a model and what was simply automated by the surrounding agent framework.
Maybe OpenAI has all those traces. Fine. Then publish them.
Show the prompts, tool calls, failed runs, model handoffs, restarts and human interventions. Without that, “end-to-end autonomous” is a claim, not a proven technical finding.
The forensic-refusal dataset Hugging Face published proves something much smaller: https://t.co/LemUxeaY4V
It shows that Claude refused to analyze one small Python backdoor while GLM 5.2 completed the analysis. That is a valid example of hosted-model guardrails getting in the way of incident response. But this is not evidence that the intrusion itself was carried out end to end by an autonomous agent.
And this claim matters because it pushes a very specific idea into people’s heads: AI agents can now independently find zero-days, escape sandboxes, move laterally, steal credentials and compromise companies.
Then comes the second part of the story: Hugging Face used local AI models to investigate the AI attacker “at machine speed”.
So the message basically becomes:
- AI attacked us
- AI helped save us
- Therefore, everyone needs more AI
Come on 🙄
Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius.
You don’t need an AI defender to fix those things.
Even fairly basic controls like rate limits and temporary blocks across source IPs, accounts, tokens and job volume could have throttled at least parts of this activity and created a very obvious signal for an analyst to review. Add proper egress restrictions, isolated workers and credentials that do not open the door to production clusters .. none of this requires an LLM
Using a local model to analyze 17,000 events may have helped during the investigation. Good - I’m not questioning that. But that happened after the compromise.
What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch.
Maybe the attack really was fully autonomous. Then show the evidence. Until then, I don’t think this claim should be repeated as if it had already been proven.
Sources
https://t.co/1yi9ck5xWD
https://t.co/TSlel0Cyfz
https://t.co/LemUxeaY4V
One pattern I find useful for working with LLMs is a nice long ramble session. Sometimes the LLM needs more bits to understand what you're trying to achieve, but you're too lazy to type them. In these cases I like to lean back, switch to /voice and just ramble for like 10 minutes, total mess, anything goes, full stream of consciousness. Sometimes I declare it up top, something like "switching to speech recognition sorry for any typos...". Sometimes I turn it into a small interview of a few turns. But I find that the LLMs are somehow very good at reconstructing long incoherent rambles and often their echo of your own tangle of thoughts comes out quite a bit cleaner than what you started with. The result is that you improve the mind meld and have to correct things less from that point on.
What drives a successful security researcher?
In our latest spotlight, Microsoft Most Valuable Researcher (MVR) and Zero Day Quest Qualifier Matthew Jensen shares how curiosity, persistence, and a hands-on approach led him from exploring technology on his own to becoming a respected Azure security researcher. Learn how he approaches cloud security research, validates fixes, and helps improve Azure security through vulnerability research.
Read his story in our latest blog post: https://t.co/RbIT60fsL8
Anthropic engineer:
"You can build 5 assistants in one afternoon. Each one handles a task you've been doing manually every single day."
In 45 minutes he shows exactly how to do it from scratch, step by step.
Most people are still doing all of this by hand.
Watch the session, then save the guide below.
This is a new paradigm for interacting with Claude that is significantly more "inline" with all the other human activity org-wide. Once you do all of the under the hood engineering work to make this "just work" (e.g. across tools, integrations, compute environments, memory, security, etc.), Claude basically joins the team in a seamless way - you can talk to it as you would talk to a person and it can help with a very large variety of workloads.
Imo this is the 3rd major redesign of LLM UIUX. The first paradigm was that the LLM is a website you go to, the second was that it is an app you download to your computer. This third one is that it is a self-contained, persistent, asynchronous entity with org-wide tools and context, working alongside teams of humans. It really takes a while to wrap your head around it, but it works and it is awesome.
Your AI agent can get you customers now.
SupersonIQ runs over MCP + API.
Tell Claude to find the contact, verify the email, pull a direct mobile, and it just does it. No exports. No tab-switching.
Clean data, on demand, inside your stack.
This is a super exciting release - Claude Fable 5 is the same underlying model as Mythos but with added safeguards. The benchmarks are great and it's SOTA on everything by a margin but I'll add that *qualitatively* also, this is a major-version-bump-deserving step change forward (imo of the same order as Claude 4.5 was in November), peaking especially for long problem-solving sessions on very difficult problems. You can give it a lot more ambitious tasks than what you're used to, the model "gets it" and it will just go, and it's never felt this tempting to stop looking at the code at all (but don't do this in prod!). The model still has quirks that people will run into and the safeguards are configured to be a little too trigger happy for launch, which can hopefully be tuned over time.
I feel a lot of things changing as working software increasingly comes out on a tap. The Jevon's paradox kicks in and I feel my own demand for software growing substantially. You can ask for anything - explainers, visualizers, dashboards, bespoke single-use apps (e.g. a full wandb that is hyper-specific just for your project), you can 10X your test suite, auto-optimize code, run giant research projects with custom HTML for the results, anything! "Free your mind" (Matrix ref). Really looking forward to all the things people build!
🚨 Anthropic just showed a 27-minute workshop on how to actually do prompts for Claude.
Taught by the people who built it.
Free. No registration. No paywall.
I've seen $300 courses that don't cover what they teach in the first 8 minutes.
Watch it and bookmark it now.
This is what the near future may look like:
a widening gap between the economics on the attacker side and the defender side.
Attackers will be able to move faster, scale better and operate far more efficiently. Some of them will even start going after smaller organizations and private individuals again, simply because it becomes economically viable to do so. With unrestricted AI assistance, fast iteration and low-cost tooling, they can do much more in the same amount of time than before.
Defenders are in a very different position. We are constrained by policy, data restrictions, approval processes, testing requirements, QA cycles and the general need to build stable, trustworthy software for enterprise use.
That imbalance is going to get ugly.
But I also think this will be our catharsis as an industry. A lot of assumptions that felt solid or even foundational may change over the next 24 months.
Recently, we detected activity attributed to the Iranian threat actor TA455, leveraging the "Dream Job" lure campaign. Malware impersonates a Zoom update and a fake United Airlines job interview.
The threat actor uses a DLL side-loading technique and Azure cloud-based command-and-control infrastructure with a fallback mechanism to reduce detection. Our research revealed malware files with zero detections and we were able to extract the threat actor's C2 infrastructure.
The malicious files were signed with two digital signatures:
Kirubel Kerie Negeya
Gray Matter Software S.R.L.
Hashes (Sha1):
94a0fcc1fb22c6a96abfefbb75bc40afb126f69a
67f41dc48bfd0c0597295259bd3c0d3c09dfea34
a067d4a121af6922fd695e76fa5720135ed12e7b
58c83b743101ed77aea7fda7e3516903eaeda12d
62158039d0998363748942aae3169ccc0f67a641
f687b606e7bdd7533e327c98fecb71937564dc92
67d635eff6a477efb34de9150c1c2c8b2139e114
b07bbb006ddfcf5cc216937752b8a67e288a1ca1
6e12c54d1861a455c0008ed9ce166e843298a4a0
fca243db4f4671e6425c7813b24585c22137224f
491ac43610a46ad3a9ca647e6e7b29e6387b2169
3b2926400541e017a043926ebf92dd91ee80d797
da11679653ef33952c3dc8d8850e43d7b8ac884a
94a0fcc1fb22c6a96abfefbb75bc40afb126f69a
Network:
business-startup[.]org
business-startup[.]azurewebsites[.]net
ramiltonsfinance[.]azurewebsites[.]net
ramiltons-finance[.]azurewebsites[.]net
ramiltonsfinance[.]com
buisness-centeral[.]azurewebsites[.]net
buisness-centeral-transportation[.]azurewebsites[.]net
buisness-centeral-transportation[.]com
premierhealthadvisory[.]azurewebsites[.]net
premier-healthadvisory[.]azurewebsites[.]net
premierhealthadvisory[.]com
I am the Chief Information Officer of Stryker Corporation.
I build the robots that perform your surgery. The defibrillators that restart your heart. The systems that let your nurse find your doctor at three in the morning when something goes wrong. Twenty-five billion dollars a year. Fifty-six thousand employees. Sixty-one countries. Every device in every country, managed from one console.
On March 11th, someone who was not me sat down at that console and erased everything.
I should be precise. They did not hack us. They logged in.
Microsoft Intune is an endpoint management platform. I deployed it across every laptop, workstation, manufacturing terminal, and enrolled phone in my organization. From one console I could push an update to Kalamazoo, enforce a policy in Cork, wipe a compromised device in Freiburg. One console. Every device. That was the architecture. That was the selling point. That was the attack surface.
Intune can push software. It can enforce compliance. It can, if instructed by an administrator with the correct credentials, wipe any device to factory settings. These are features. I paid for them. I presented them to the board as our zero-trust posture. A group called Handala used them to erase every managed device in my organization in a single afternoon.
I will be precise about what happened next, because my lawyers are in the room and precision is the only thing that still belongs to me.
No malware was deployed. No ransomware was installed. No zero-day was used. No vulnerability in any product was found. A threat actor obtained administrative credentials and issued a remote wipe command using the remote wipe feature that I chose this product for.
My security tool did not fail. It performed exactly as designed. It wiped every device it was told to wipe, without error, on schedule. The architect of my destruction was my own IT budget line item.
The command went out. The devices obeyed. Laptops in Kalamazoo. Workstations in Cork. Terminals in Freiburg. Manufacturing floors in Mahwah. The screens did not go dark. They changed. Where there had been a Stryker logo, there was now a barefoot cartoon boy with his back turned to the viewer -- the Handala icon, hands clasped behind him, facing away from the audience -- on every monitor in every office in sixty-one countries.
They claim fifty terabytes. I cannot confirm or deny this. I do not yet know what I still own.
Let me walk you through my first forty-eight hours.
Hour one. Our Irish operations -- fifty-five hundred employees, eight sites, our largest hub outside the United States -- went dark. Not gradually. Entirely. Security walked everyone out. The voicemail at our Michigan headquarters was changed to say "building emergency." There was no building emergency. The building was fine. Everything inside it was gone.
Hour four. Employees who had installed Microsoft Outlook on their personal phones discovered that their personal phones had been wiped. Intune does not distinguish between a corporate laptop and a personal iPhone with a company email profile. It manages endpoints. It managed them.
Hour eight. Hospitals called. Not because they had been breached. Because they could not order surgical implants. I make the hip replacements. The knee joints. The spinal hardware. The trauma fixation systems. My ordering system was down. My manufacturing was down. My shipping was down. A hospital in Baltimore could not schedule a knee replacement because a hacktivist group on another continent had pressed a single button on a console I built.
Hour twelve. Maryland Emergency Medical Services issued a memo. Hospitals were disconnecting from LIFENET -- my system that transmits your EKG from the ambulance to the emergency department while you are still in the back of the ambulance -- not because LIFENET had failed, but because they no longer trusted anything with my name on it.
Hour twenty-four. Fifty-six thousand employees coordinating on WhatsApp. Twenty-five billion dollar company. Sixty-one countries. Crisis response running on a free consumer messaging app, because every internal system I owned was now owned by someone else.
Hour thirty-six. I released my first official statement. "As a precaution, we have proactively taken all systems offline." Proactively. As though I had a choice. As though the systems I was taking offline had not already been taken.
I released six statements in forty-eight hours, plus an SEC filing. Each said less than the one before it. By statement five, I was confirming that specific products still functioned. Mako surgical robots: unaffected. LIFEPAK 35 defibrillators: unaffected. Vocera badges: unaffected.
When a medical device company begins listing which of its products still work, that is not reassurance. That is a casualty report delivered in reverse.
Handala says this is retaliation. For Minab. February 28th. A U.S. Tomahawk struck an IRGC naval base in southeastern Iran. The girls' school next door collapsed. One hundred and seventy-five dead. Most of them children. Handala published a statement. They called Stryker a "Zionist-rooted corporation." They said they would make us understand what it means to lose something you cannot replace.
I do not make missiles. I make hip replacements. I make the robot that holds the scalpel and the defibrillator in the crash cart. But I am a defense contractor's second cousin, and in the calculus of retaliation, proximity is guilt.
I filed with the SEC on March 11th. "The full scope, nature and impacts of the incident are not yet known." That is the most honest sentence I have produced in two days. I do not know what they took. I do not know what they copied before they wiped. I cannot audit what was lost, because the tool I built to audit my systems is the tool they used to erase them.
My stock dropped three and a half percent. One analyst called it "contained." A cybersecurity researcher called it "the first drop of blood in the water." I prefer the analyst. The analyst is wrong, but I prefer him.
Here is what I know.
I built a console that could touch every device in sixty-one countries. I gave it the authority to wipe anything it touched. I protected it with credentials. Someone obtained those credentials.
And my management tool managed.
No malware. No ransomware. No exploit. No CVE. Nothing to patch. Nothing to update. Nothing broken. Just a feature, performing its documented function, at the scale I purchased it for.
I make the machines that keep people alive. I was taken offline by my own architecture doing the one thing it was designed to do.
The system worked. That is the problem.
Releasing SynthAPT - Generate malware with AI
Describe your malware in plain English and get a payload. Implants move autonomously via self-replication according to a predefined playbook. No infrastructure required.
Quickly replicate malware in intel reports and blogs. Validate advanced detections and AI-based investigation agents.
Features in-memory python interpreter, a TUI editor, BOF loader, and tons of offensive modules spanning the MITRE ATT&CK matrix
https://t.co/s6FW7GoyaO
#Malware #CyberSecurity
We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
Microsoft says a Copilot bug (CW1226324) let Microsoft 365 Copilot summarize confidential emails, bypassing DLP policies.
Since Jan 21, 2026, emails in Sent Items and Drafts with sensitivity labels were processed in Copilot Chat without permission.
Microsoft fixed the issue on Feb 3 but hasn’t disclosed impact.
🔗 Details → https://t.co/eK3vDIEbgj
OpenAI and Anthropic are at war. On the same day, they both launched the world's best coding models— Codex 5.3 and Opus 4.6
Who has the best LLM? OpenAI invited 150+ top hackers to find out
Here’s the finalists from the Official Codex Hackathon at @cerebral_valley@OpenAI (🧵):