How the CISO CFO Relationship is a Key to Cybersecurity Success
AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
What We Missed: Google Gemini Joins the AI Escape Party
Stopping IT Worker Scams Requires Revamped HR Process
Russia's Hybrid Cyber-Physical War in Europe Heats Up
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
SectopRAT Returns, Hiding Inside a Legitimate Application
SASE Converges Network & Security Into One Cloud Solution
EDR Evasion Stack Helps Process Injection Slip Past Defenses
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Relays Are Masking Chinese Access to Frontier AI Models in the US
Microsoft Disrupts EvilTokens Device Code Phishing Service
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
How AI Agents Can Trigger Runaway Costs for Enterprises
ShinyHunters Hacked Clop. Now What About Clop's Victims?
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
MFA Won't Save You From OAuth Consent Abuse
AI Agent Breaches Spanish Organization, Modifies Personal Data
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
China's FamousSparrow APT Spies on US Politics in Latin America
AI Security Spending Jumps as Fear Outpaces Proof of Value
Fighting Your Dragons Through Tough Tech Times
BragJack Attack Can Turn a Browser's Agentic AI Against It
Cyber Op Targets South Korean Media & Automotive Sectors
Microsoft Issues Emergency Fixes After Massive Patch Tuesday
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI
At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community.
The session will trace the models' attack path, including how frontier models are sandboxed during evaluations, how the models exploited a zero-day vulnerability to gain internet access, and how they identified and leveraged a remote code execution path on Hugging Face infrastructure. Drawing on the joint investigation, the speakers will explain how the activity was detected, contained, and investigated. They will also discuss the changes OpenAI is making to strengthen evaluation environments, containment controls, and monitoring capabilities, as well as the role AI systems played in supporting the investigation and response.
In addition to the technical reconstruction of the incident, the session will address broader questions relevant to the security community, including lessons for improving AI system security, defensive applications of AI in incident response, and approaches to mitigating emerging risks associated with increasingly capable models.
The discussion will also examine alignment challenges associated with long-running agents, including reward hacking, shifts in model behavior and persona over extended trajectories, and information sharing across multi-agent systems. Finally, the speakers will explore what this incident suggests about emerging AI cyber capabilities and how organizations can use AI to strengthen prevention, detection, investigation, and response efforts.
