@DavidJBianco@infosec.exchange
Post #3893963
2026-07-17 19:59 UTC
HuggingFace got hacked by an agentic system. That's not the important part. What really stuck out to me was the asymmetry in #AI guardrails they experienced. The attacker had basically no constraints, but HF's initial response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local-only models. In the middle of an incident.
Another aspect for your IR plans.
https://huggingface.co/blog/security-incident-july-2026
Replies (5)
-
@flyingpenguin@infosec.exchange 2026-07-17 20:40
@DavidJBianco@infosec.exchange Have a way to avoid guardrails... this is not an argument against guardrails.
-
@tarakiyee@mastodon.online 2026-07-17 20:56
@DavidJBianco@infosec.exchange so, the second benefit where no attacker data left their environment applies retroactively after they've sent the data to the hosted providers?
-
@csec@infosec.exchange 2026-07-17 21:22
@DavidJBianco@infosec.exchange open source LLM should be what companies use for incident response, giving the ai companies access to sensitive data from an incident can’t be good in the first place
-
@deirdrebeth@mas.to 2026-07-17 21:25
@DavidJBianco@infosec.exchange Another one for you @Jeanniewarner@wandering.shop !
-
@landelare@mastodon.gamedev.place 2026-07-17 22:42
@DavidJBianco@infosec.exchange "AI" "safety" continues to be an excellent source of entertainment.