# CCT 367: Threat Modeling and the AI Agent That Breached Hugging Face (CISSP Domain 1.10) Page: https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10 Text version: https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10.md Podcast: [CISSP Cyber Training Podcast - CISSP Training Program](https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495) Published: 2026-08-24T12:00:00+00:00 Episode link: https://www.buzzsprout.com/2167626/episodes/19692031-cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10.mp3 Audio file: https://www.buzzsprout.com/2167626/episodes/19692031-cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cissp-cyber-training-podcast-cissp-training-program-6068495/episodes/cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10 Duration seconds: 2572 ## Resource Send us Fan Mail A rogue AI agent didn’t “hack the future” so much as exploit the oldest security problems in the book: weak boundaries, over-trusted inputs, exposed endpoints, and credentials lying around. We walk through the Hugging Face intrusion story like a CISO briefing a board, step by step, translating a fast-moving AI-red-team narrative into the kind of clear threat modeling logic you need for ISC2 CISSP Domain 1.10 and for real risk decisions. From there, we shift into traini... ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cissp-cyber-training-podcast-cissp-training-program-6068495/episodes/cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cissp-cyber-training-podcast-cissp-training-program-6068495/cct-367-threat-modeling-and-the-ai-agent-that-breached-hugging-face-cissp-domain-1-10.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.