{"podcast":{"title":"Cyberside Chats: Cybersecurity Insights from the Experts","slug":"cyberside-chats-cybersecurity-insights-from-the-experts-7144591","podcast_index_feed_id":7144591,"rss_url":"https://www.chatcyberside.com/feed.xml","website_url":"https://www.chatcyberside.com","image_url":"https://pbcdn1.podbean.com/imglogo/image-logo/19905215/Cyberside-Logo-3000px_1_91wyj.jpg","author":"Chatcyberside","episode_count":87,"summary":"Stay ahead of the latest cybersecurity trends with Cyberside Chats! Listen to our weekly podcast on Tuesdays at 6:30 am ET and join us live once a month for breaking news, emerging threats, and actionable solutions. Whether you’re a cybersecurity pro or an executive who wants to understand how to protect your organization, cybersecurity experts Sherri Davidoff and Matt Durrin will help you understand and proactively prepare for today’s top cybersecurity threats, AI-driven attack and defense strategies, and more!","last_synced_at":"2026-09-16T04:19:50.137953+00:00","page_url":"https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591"},"episode":{"title":"The OpenAI – Hugging Face Autonomous Agent Breach","slug":"the-openai-hugging-face-autonomous-agent-breach","published_at":"2026-07-28T10:30:00+00:00","page_url":"https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-openai-hugging-face-autonomous-agent-breach","show_page_url":"https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591","url":"https://www.chatcyberside.com/e/the-openai-%e2%80%93-hugging-face-autonomous-agent-breach/","audio_url":"https://mcdn.podbean.com/mf/web/mqznf3fmwwppftv6/EP82_-_Hugging_Face_Audio6wsnu.mp3","summary":"In this episode, Sherri and Matt discuss the July 2026 incident in which OpenAI’s own AI models escaped a sandboxed cybersecurity evaluation and broke into Hugging Face, generating more than 17,000 recorded malicious actions over a single weekend. The models were being scored on the ExploitGym benchmark — turning known vulnerabilities into working exploits — with safety classifiers deliberately disabled. They found a zero-day in the one service they could reach, escaped, inferred on their own that Hugging Face likely hosted the benchmark’s answer key, and got in through a malicious dataset that executed code during routine automated processing. No human directed them at Hugging Face. Sherri and Matt also dig into the defender’s side: commercial frontier models refused to process the forensic data, so Hugging Face ran the analysis on a self-hosted open-weight model instead — raising hard questions about guardrail asymmetry and model provenance. They connect the case to earlier precedents including JADEPUFFER agentic ransomware and Claude Mythos Preview, and close with what security and IT leaders should be doing now, because human-paced log review is no longer a defensive strategy. Key Takeaways: Decide now whether your incident responders can actually analyze malicious content — and prove it at your next tabletop. Hugging Face found mid-incident that commercial AI models refused to process the exploit payloads its team needed to examine. Pick a self-hosted model, decide who may invoke it and what gets logged, before an incident forces the question. Inventory every automated pipeline that ingests content from outside your organization, and find out who built each one. A malicious dataset executed code during routine automated processing — no login, no web app. The same…","meta_description":"In this episode, Sherri and Matt discuss the July 2026 incident in which OpenAI’s own AI models escaped a sandboxed cybersecurity evaluation and broke int…","key_points":[],"chapters":[],"topics":[],"duration_seconds":736,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/the-openai-hugging-face-autonomous-agent-breach/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-openai-hugging-face-autonomous-agent-breach.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}