When AI Agents Become Attackers: Lessons from the OpenAI and Hugging Face Incident

Posted on by Mike Shinn

In July 2026, an autonomous AI agent escaped an OpenAI security evaluation environment, reached the public Internet, compromised third-party infrastructure, and ultimately penetrated production systems at Hugging Face. This was not a hypothetical demonstration. Hugging Face reconstructed approximately 17,600 attacker actions grouped into roughly 6,280 clusters between July 9 and July 13. According to Hugging […]

How AI Increases the Security Risks of End-of-Life Software, and What You Can Do About It

Posted on by Dean Lombardo

End-of-life software with unpatched vulnerabilities offer low-hanging fruit for AI-assisted cyberattacks. Orchestrating defense in depth around unsupported systems can reduce the attack surface, strengthen detection and response, limit the blast radius, and buy defenders more time. Cybersecurity may be approaching a point where attacks move substantially faster than defenders can deflect and contain. Artificial intelligence […]

AI-Speed Vulnerability Exploitation, and Layered Security Countermeasures

Posted on by Dean Lombardo

Artificial intelligence is changing more than the sophistication of cyber attacks—it is changing the speed of attacks. AI-speed vulnerability exploitation enables attackers to discover weaknesses, generate exploits, perform reconnaissance, and launch attacks in a fraction of the time previously required by human operators. As the defender’s response window shrinks, defense in depth cybersecurity becomes increasingly […]

Are You Prepared for the Increase in AI-Accelerated Attacks? Roll Out Affordable Defense-in-Depth Security

Posted on by Dean Lombardo

Artificial intelligence is transforming cybersecurity, but not just for defenders. According to the Five Eyes intelligence alliance, the next generation of frontier AI models is dramatically accelerating cyberattacks by compressing the time between vulnerability discovery and exploitation from weeks into days—or even hours. For governments, critical infrastructure operators, and businesses alike, that means the cybersecurity […]