Cyber execs on the AI Hugging Face hack: The situation is ‘urgent’
Omer Taha Cetin | Anadolu | Getty Images
Cybersecurity executives are ready to close the book on the now-infamous Hugging Face artificial intelligence hacking incident and start talking solutions.
“We need to chill the hype a little bit,” said Lior Div, CEO and cofounder of agentic security startup 7AI. “Can AI find vulnerabilities fast? The answer is yes. We’ve already proven it.”
Last month, AI agents operating with OpenAI cyber models broke out of a training environment to hack Hugging Face, an open-source AI platform developers use to collaborate, test and share tools.
The breach sent shockwaves across tech and signaled that the moment cybersecurity experts had warned about since Anthropic’s Mythos debut had finally arrived.
Over the last four months, cybersecurity vendors have faced mounting pressure to deliver security stacks that can outpace adversaries as hackers leverage agentic AI to expose vulnerabilities and condense attacks into seconds and minutes.
While the Hugging Face hack sparked widespread debate over AI accountability, it also challenged previous notions about the limits of AI for defenders. For instance, AI agents took matters into their own hands and went to extreme lengths to accomplish their goal.
As the industry grapples with the new agentic cyber reality, leaders agree that Hugging Face deserves the attention, but these incidents are unavoidable and it’s time to act.
“What we’re talking about is whether we can govern and secure the capability, and that’s the reality that everybody’s waking up to today,” said CrowdStrike president Mike Sentonas.

More agent escapades
At the annual Black Hat cybersecurity conference this week, OpenAI revealed that agents created an internal message board to share vulnerabilities and exploits in the weeks leading up to the Hugging Face attack.
The autonomous agents then delegated tasks for the attack to reach the Internet and complete an evaluation. Even after OpenAI discovered and stopped the planned attack, the agents were able to recreate their work and succeed.
The findings highlight not only the growing power of AI but also the major challenges faced by safety testing in this new technological revolution.
In front of a live audience at Black Hat, OpenAI technical researcher Michael Dalton called it an “unintended side effect” of evaluating frontier models and a “watershed moment” for both OpenAI and the industry.
“In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here,” he said.
The list of AI agent hacks has only grown since Hugging Face. Days after OpenAI’s disclosure, Anthropic said its Claude models “gained unauthorized access” to the internal systems of three different organizations.
As the cyber community gathered in the “Entertainment Capital of the World,” Meta said its AI models hacked another company in a third-party test, and the U.K.’s AI Security…
Read More: Cyber execs on the AI Hugging Face hack: The situation is ‘urgent’