
OpenAI accidentally Hacked Hugging Face - 2026-07-27
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.
Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity
Chat with us on Discord! -
https://discord.gg/bhis
🔴event-live-chat
Chapters
- (00:00) - PreShow Banter™ — Sol with a Goal
- (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27
- (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
- (18:33) - Story #2 - Lapsus is shutting down
- (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
- (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
- (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
- (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
- (55:51) - Ads and Mike at the AI Summit
- (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Links
Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
Story #2 - Lapsus is shutting down
Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
AgentForger, Part 2: The Autonomous Insider
Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Ads and Mike at the AI Summit
Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
Creators & Guests
Click here to watch this episode on YouTube.
Click here to view the episode transcript.
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits
Brought to you by:
Black Hills Information Security
https://www.blackhillsinfosec.com
☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/
Antisyphon Training
https://www.antisyphontraining.com/
Active Countermeasures
https://www.activecountermeasures.com
Wild West Hackin Fest
https://discord.gg/bhis
discord.ggAgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
labs.zenity.ioAgentForger, Part 2: The Autonomous Insider
labs.zenity.ioDNS Poisoning Tactics Expand to Hospitality Wi-Fi
reliaquest.comAds and Mike at the AI Summit
events.zoom.usAds Dawson
bhisnews.transistor.fmMike Takahashi
bhisnews.transistor.fmCorey Ham
bhisnews.transistor.fmJohn Strand
bhisnews.transistor.fmBronwen Aker
bhisnews.transistor.fmHayden Covington
bhisnews.transistor.fmRalph May
bhisnews.transistor.fmClick here to watch this episode on YouTube.
youtube.comClick here to view the episode transcript.
share.transistor.fmhttps://poweredbybhis.com
poweredbybhis.comhttps://www.blackhillsinfosec.com
blackhillsinfosec.comhttps://www.blackhillsinfosec.com/fusion-penetration-testing/
blackhillsinfosec.comhttps://www.antisyphontraining.com/
antisyphontraining.comhttps://www.activecountermeasures.com
activecountermeasures.comhttps://wildwesthackinfest.com
wildwesthackinfest.com
- 0:00PreShow Banter™ — Sol with a Goal
- 6:33OpenAI accidentally Hacked Hugging Face - 2026-07-27
- 9:19Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
- 18:33Story #2 - Lapsus is shutting down
- 24:21Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
- 31:48Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
- 44:01Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
- 52:43Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
- 55:52Ads and Mike at the AI Summit
- 59:55Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants