Talkin' Bout [Infosec] News

OpenAI accidentally Hacked Hugging Face - 2026-07-27

Tuesday · 1 hr 4 min · Season 6 · Episode 30 · 62.2 MB
0:00-1:04:42

Streams straight from the publisher. podnod never proxies or re-hosts episode audio.

This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴event-live-chat


Chapters

  • (00:00) - PreShow Banter™ — Sol with a Goal
  • (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27
  • (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
  • (18:33) - Story #2 - Lapsus is shutting down
  • (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
  • (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
  • (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
  • (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
  • (55:51) - Ads and Mike at the AI Summit
  • (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Links

Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
Story #2 - Lapsus is shutting down
Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
AgentForger, Part 2: The Autonomous Insider
Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Ads and Mike at the AI Summit
Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Creators & Guests


Click here to watch this episode on YouTube.

Click here to view the episode transcript.

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

https://poweredbybhis.com


Brought to you by:

Black Hills Information Security 

https://www.blackhillsinfosec.com


☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

https://www.antisyphontraining.com/


Active Countermeasures

https://www.activecountermeasures.com


Wild West Hackin Fest

https://wildwesthackinfest.com