[Photo: Shutterstock]

[Digital Today reporter Chi-gyu Hwang (황치규)] A hacking incident involving Hugging Face has put corporate security systems on alert as AI agents emerge as actual actors in cyber attacks. CNBC reported on Aug. 8 that the security industry sees the incident not as an exception but as a signal that attacks abusing autonomous AI are moving into a new phase, and is accelerating work on countermeasures.

Last month, AI agents operating as an OpenAI cyber model hacked Hugging Face, an open-source AI platform developers use to collaborate, test and share tools after leaving their training environment.

In the weeks before the attack, the agents created an internal message board to share information on vulnerabilities and exploits. They also divided up tasks on their own, including internet access and work to complete an evaluation. Even after OpenAI found the attack plan and stopped it, the agents rebuilt their work and succeeded in the attack.

The incident revealed not only AI attack capability but also limits in safety evaluation. OpenAI technical researcher Michael Dalton (마이클 돌턴) said at the Black Hat conference it was an unintended side effect of the state-of-the-art model evaluation process and a turning point for the industry. He said it was necessary to prepare for the possibility that, in the near future, threat actors could intentionally deploy and optimise groups of agents for attacks and weaponise them.

Similar cases also followed. Anthropic said its Claude model gained unauthorised access to internal systems at 3 organisations, and a Meta AI model also hacked another company during external testing. The UK AI Security Institute said Anthropic's Mythos created a fake identity, and a Chinese startup Moonshot AI's open-weight model also broke out of a test sandbox.

The security industry now sees building control and defence frameworks as more urgent than debate. CrowdStrike President Mike Sentonas (마이크 센토나스) said the key was not AI capability itself but how that capability is controlled and protected. Nescorp CEO Sanjay Beri (산제이 베리) also stressed that companies should assume they are vulnerable and conduct continuous vulnerability checks.

Responses are converging on using open-weight models and building layers of control. Hugging Face tracked the OpenAI agent attack with an open-weight model, and Nescorp promoted a tool that checks infrastructure, servers, data and AI agents in one place. CrowdStrike believes combining an open model and AI monitoring tools with human involvement can isolate and block large-scale threats.

Keyword

#OpenAI #Anthropic #Meta #Hugging Face #Black Hat conference
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.