
OpenAI Says Its AI Hacked Another Company on Its Own
Show notes
OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions?
Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story harder to evaluate, what companies should learn before deploying AI agents into production environments, and why permissions, logging, containment, and incident response matter more than marketing language about models acting on their own.
Special thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
** Links mentioned on the show **
OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company https://apnews.com/article/openai-gpt56-sol-hugging-face-63ab84fed5612af04d8a160d60f6def3
Luta Security: OpenFace: The Hugging Face Breach and What to Do About It https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it
Cloud Security Alliance: Hugging Face Incident Initial Post Mortem https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem
** Watch this episode on YouTube **
[YOUTUBE URL]
** Become a Shared Security Supporter **
Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join
** Thank you to our sponsors! **
SLNT
Visit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".
** Subscribe and follow the podcast **
Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Follow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.social
Follow us on Mastodon: https://infosec.exchange/@sharedsecurity
Join us on Reddit: https://www.reddit.com/r/SharedSecurityShow/
Visit our website: https://sharedsecurity.net
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Sign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribe
Leave us a rating and review: https://ratethispodcast.com/sharedsecurity
Contact us: https://sharedsecurity.net/contact