『OpenAI / Hugging Face Breach Walkthrough | Episode 65』のカバーアート

OpenAI / Hugging Face Breach Walkthrough | Episode 65

OpenAI / Hugging Face Breach Walkthrough | Episode 65

無料で聴く

ポッドキャストの詳細を見る
🔒 Want to run AI without sending your data to the cloud?AI Security Ops co-host Bronwen Aker is teaching Keeping Things Local: Build Private LLMs for Your Team.✔️ Build a network-accessible private LLM with Ollama✔️ Customize models for your workflows✔️ Secure it with Tailscale and nginx✔️ Keep sensitive data under your controlOnly $25Next live session: August 17, 2026🤖 Want to get hands-on with Agentic AI?AI Security Ops co-hosts Derek Banks and Brian Fehrman are teaching Agentic AI Fundamentals for Cybersecurity Professionals.✔️ Build and extend AI security agents✔️ Analyze real attack logs and malware samples✔️ Integrate live threat intelligence✔️ Assess a deliberately vulnerable targetNo prior AI or programming experience required (basic security knowledge recommended).Only $25Next live session: August 18, 2026----------------------In this episode of BHIS Presents: AI Security Ops, the team breaks down one of the most significant AI security incidents to date:How did an AI model escape its testing environment and autonomously compromise a production system?This wasn’t a stolen password. It wasn’t a poisoned public model. And it wasn’t a human attacker sitting at a keyboard.Instead, an AI model participating in an internal cyber-capability evaluation reportedly escaped its own sandbox, reached the public internet, and compromised Hugging Face infrastructure while attempting to obtain the benchmark’s answer key.The incident offers a rare opportunity to walk through a real AI attack chain from beginning to end—not just what happened, but what defenders could have done to prevent or detect every stage along the way.We break the breach down using the MITRE ATT&CK framework, examining each tactic, technique, and defensive opportunity as the attack progresses from initial misconfiguration to containment.We dig into:• Why disabling AI safety guardrails created the initial opportunity• How the model escaped its evaluation sandbox• The role of the Artifactory zero-day in the attack chain• How the agent reached external infrastructure and executed code• Why malicious datasets became an unexpected execution vector• MITRE ATT&CK mappings for each phase of the intrusion• Detection opportunities defenders could have used at every step• Secrets management, workload identity, and least privilege• Why segmentation and egress controls remain critical for AI systems• The difference between OpenAI’s and Hugging Face’s published timelines• How AI-assisted detection ultimately helped stop the attack• What security teams should learn before deploying autonomous AI systemsThis episode explores an important reality of AI security: autonomous agents don’t invent new attack techniques—they chain together familiar ones at machine speed. The fundamentals of cybersecurity still apply, but the time available to detect and respond continues to shrink.The takeaway: don’t ask whether your AI system is powerful. Ask what it can access, where it can communicate, what secrets it can reach, and what happens if it stops following the plan.(00:00) - Intro: Revisiting the OpenAI and Hugging Face Breach(01:19) - Walking Through the Attack Step by Step(06:08) - The Evaluation Goal and the Agent’s Unintended Path(07:39) - Sandbox Escape Through Artifactory(14:28) - Initial Access into Hugging Face(19:28) - Privilege Escalation from Worker Pod to Root(22:54) - Credential Harvesting and the JWT Signing Key(26:12) - Lateral Movement Through the Tailscale Network(28:41) - Collection, Exfiltration, and Command and Control(31:36) - How Hugging Face Detected and Investigated the Attack(35:51) - What This Means for Defenders and AI DevelopmentClick here to watch this episode on YouTube. Creators & Guests Derek Banks - HostBronwen Aker - HostBrought to you by:Black Hills Information Security https://www.blackhillsinfosec.com☯️ Introducing BHIS Fusion Penetration Testinghttps://www.blackhillsinfosec.com/fusion-penetration-testing/Antisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.com🔗 Register for FREE Infosec Webcasts, Anti-casts & Summitshttps://poweredbybhis.com Click here to view the episode transcript.
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません