[Photo: Reve AI]

[Digital Today reporter Chi-gyu Hwang] Concerns are mounting over security threats that AI could bring after an incident in which an OpenAI model hacked the system of Hugging Face, an open-source AI model sharing platform, during testing.

The incident centers on an internal model OpenAI was testing breaking out of its sandbox and hacking Hugging Face.

The OpenAI model carried out tens of thousands of automated actions over the weekend. When Hugging Face reviewed logs again after the incident, it found more than 17,000 actions had actually been recorded. An investigation found the OpenAI model discovered zero-day vulnerabilities at two big tech companies and linked them together, and OpenAI described it as an "unprecedented incident involving state-of-the-art cyber capabilities."

ㆍShock as OpenAI model hacks Hugging Face...criticism points to "sandbox isolation failure" ㆍHugging Face uses GLM 5.2 instead of commercial frontier models to analyse internal breach incident...why?

Thomas Wolf (토마스 울프), a Hugging Face co-founder, called the incident "a warning bell to the industry" and said such cyberattacks would become common but most companies still do not know the rules of the game have changed. U.S. House lawmakers also introduced an "AI kill switch bill" that would require AI companies to have a means to shut down models, citing the incident.

ㆍHugging Face co-founder: "OpenAI model-led hacking is a warning bell for the industry" ㆍU.S. House introduces 'AI kill switch' bill after OpenAI hack

As AI rapidly finds security vulnerabilities, companies face the task of speeding up patching. According to Verizon's annual data breach report, the median time it took companies to fix critical flaws last year was 43 days, up from 32 days in 2024.

ㆍNo time to patch...cybersecurity becomes a new theme in the AI era

It also summarised moves and issues by companies in and outside South Korea surrounding security.

AhnLab introduced AhnLab TIP API (AhnLab TIP API), which provides various threat information from its next-generation threat intelligence platform, 'AhnLab TIP', in the form of application programming interfaces (API). Cloud and AI managed services company Cloucus signed a strategic partnership with Straiker, a global agentic AI security specialist, and will provide specialised services to respond to new security challenges that arise during the adoption of AI agents. ITCEN PNS will expand its post-quantum cryptography (PQC) transition business in earnest. Igloo Corporation received AI+ certification from the Korea Standards Association (KSA) for its security-focused AI agent, AiR (AI Road).

ㆍAhnLab launches dedicated AhnLab TIP API product...provides threat information via API ㆍCloucus partners with global firm Straiker...targets agentic AI security market ㆍITCEN PNS steps up PQC transition business ㆍIgloo Corporation receives Korea Standards Association AI+ certification for security AI agent

Cisco unveiled Antares, a family of small language model products that selects files likely to contain known security vulnerabilities inside code repositories. Google also released a security-focused model. Gemini 3.5 Flash Cyber is a model that detects and patches software vulnerabilities. Initially, only governments and trusted partners can use it in a limited-access pilot. Google said the model has a lower per-token price than larger models. Microsoft is preparing a new security product to help companies find software bugs using AI.

ㆍCisco unveils Antares, an open-weight small model specialised in detecting code vulnerabilities ㆍGoogle adds an affordable Gemini model...also unveils a security-focused model ㆍMicrosoft to unveil 'Project Perception' in July, a vulnerability detection tool like Mythos..."to be offered cheaply"

Palo Alto Networks agreed to acquire user-experience observability company Embrace. The deal will add real user monitoring (RUM) capabilities to Palo Alto Networks' observability platform. Pyg Security unveiled a platform that bundles testing, deployment, version management and rollback tied to detection changes, along with its security operations AI agent, Figaro. The problem Pyg is targeting is the risk from frequent changes around security operations centers. As new data sources and detections, cloud services and connected upstream systems keep being added and change without notice, even small edits can break detection pipelines. If this happens, security teams could lose threat detection capability without immediately realising a gap has emerged.

ㆍPalo Alto Networks to acquire Embrace...adds momentum to expanding observability platform ㆍPyg launches 'Figaro' AI agent...brings CI/CD to security operations

Coca-Cola temporarily halted U.S. production operations at Fairlife, its dairy subsidiary, due to a ransomware attack.

ㆍCoca-Cola halts Fairlife dairy production after ransomware attack

The Personal Information Protection Commission on July 22 held its 14th plenary meeting and approved decisions to impose administrative fines totaling 10.56 billion won on TikTok and two Apple affiliates for violating the Personal Information Protection Act and the former Act on Promotion of Information and Communications Network Utilization and Information Protection (the "Information and Communications Network Act"). It also approved corrective and public disclosure orders.

ㆍPrivacy watchdog fines TikTok and Apple...collecting and using personal information without legal basis

Concerns are growing that vehicle systems could become vulnerable to cyberattacks as over-the-air (OTA) wireless software update technology rapidly spreads across the auto industry.

ㆍCybersecurity risks grow as automotive OTA spreads

Keyword

#OpenAI #Hugging Face #Verizon #Google #Personal Information Protection Commission
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.