OpenAI accidentally Hacked Hugging Face - 2026-07-27
S6:E30

OpenAI accidentally Hacked Hugging Face - 2026-07-27

This week, the crew digs into one of the biggest AI security stories of the year: how an OpenAI autonomous agent accidentally compromised a Hugging Face environment during testing and what the incident reveals about the growing risks of agentic AI. They examine how AI models behave in offensive security scenarios, discuss emerging attack surfaces around MCPs and AI agents, explore the challenges of AI red teaming, and debate what organizations should be doing today to secure AI-powered workflows. The episode also covers AI safety initiatives, model behavior, and where defensive security is struggling to keep pace with rapidly evolving AI capabilities.

Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurity

Chat with us on Discord! -
https://discord.gg/bhis
🔴event-live-chat


Chapters

  • (00:00) - PreShow Banter™ — Sol with a Goal
  • (06:33) - OpenAI accidentally Hacked Hugging Face - 2026-07-27
  • (09:18) - Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
  • (18:33) - Story #2 - Lapsus is shutting down
  • (24:21) - Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
  • (31:47) - Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
  • (44:00) - Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
  • (52:43) - Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
  • (55:51) - Ads and Mike at the AI Summit
  • (59:54) - Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Links

Story #1 - OpenAI says it accidentally hacked Hugging Face with a new AI system
Story #2 - Lapsus is shutting down
Story #3 - AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery
AgentForger, Part 2: The Autonomous Insider
Story #4 - Beyond the Terminal: Offensive Security Evals for Embodied Reasoning
Story #5 - EXPLOIT BROKERS PAY $500,000 FOR A WORDPRESS RCE. I FOUND ONE WITH GPT5.6 SOL ULTRA AND $25
Story #6 - DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Ads and Mike at the AI Summit
Story #7 - Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Click here to watch this episode on YouTube.




🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits 

Brought to you by:
Black Hills Information Security 

☯️ Introducing BHIS Fusion Penetration Testing
https://www.blackhillsinfosec.com/fusion-penetration-testing/

Antisyphon Training

Active Countermeasures

Wild West Hackin Fest

Episode Video

Creators and Guests

Bronwen Aker
Host
Bronwen Aker
Bronwen Aker is a BHIS Technical Editor who joined full-time in 2022 after years of contract work, bringing decades of web development and technical training experience to her roles in editing pentest reports, enhancing QA/QC processes, and improving public websites, and who enjoys sci-fi/fantasy, Animal Crossing, and dogs outside of work.
Corey Ham
Host
Corey Ham
Corey Ham has been with Black Hills Information Security (BHIS) since 2021 delivering red teaming and OSINT services. Currently, Corey leads the ANTISOC team at BHIS, providing subscription-based continuous red teaming to BHIS clients. Outside of his time at BHIS, you can find him out in the woods or up on a mountain somewhere.
Hayden Covington
Host
Hayden Covington
Hayden Covington joined Black Hills Information Security (BHIS) in the Summer of 2022 as a SOC Analyst. He chose BHIS after hearing many great things over the years and seeing the quality of work, as well as finding people who have the same passion for the field as he does. His favorite part of the job so far has been the community. Previously, Hayden worked in a SOC for a Naval contractor, where he also served as their SOAR project manager and SME, as well as insider threat lead. When he’s not working, Hayden can be found doing anything athletic (like triathlons!), as well as enjoying video gaming and Formula 1.
John Strand
Host
John Strand
John Strand has both consulted and taught hundreds of organizations in the areas of security, regulatory compliance, and penetration testing. He is a coveted speaker and much loved SANS teacher. John is a contributor to the industry-shaping Penetration Testing Execution Standard and 20 Critical Controls frameworks.
Ralph May
Host
Ralph May
Ralph is a U.S. Army veteran and former DoD contractor who supported the United States Special Operations Command (USSOCOM) with information security challenges and threat actor simulations. Over the past decade, he has provided offensive security services at Optiv Security and Black Hills Information Security (BHIS) across various industries. His expertise spans network, physical, and wireless penetration testing, social engineering, and advanced adversarial emulation through red and purple team assessments. Ralph has developed several tools, including Bitor (set to release in January 2025) and Warhorse, which enhance efficiency in penetration testing infrastructure and operations. He has spoken at numerous conferences, including DEF CON, Black Hat, Hack Miami, B-Sides Tampa, and Hack Space Con.
Ads Dawson
Guest
Ads Dawson
Ads Dawson has spent the past year stealing data from AI agents in production — through bug bounty programs. A Staff AI Security Researcher at Dreadnode and member of BT6, the frontier AI red team, he specializes in web application security, adversarial machine learning exploitation, and autonomous red teaming. Ranked #2 in Canada on HackerOne (2026) and #1 Up and Comer (Q4 2025), Ads is a HackerOne Ambassador (US South), BugCrowd Hacker Advisory Board member, and selected for Meta’s MBBRC live hacking event. He founded the OWASP GenAI Security Project — the fastest project to reach OWASP flagship status — and is lead author of AIRTBench (arXiv), the first AI/ML red teaming benchmark for LLMs. His work includes red teaming frontier models for Google DeepMind and shaping the EU AI Act Code of Practice.
Mike Takahashi
Guest
Mike Takahashi
Mike Takahashi, aka TakSec, is an AI Red Team Researcher at Zenity, BT6 member, and Bug Bounty Hunter focused on breaking AI systems. He has submitted 400+ vulnerabilities across major bug bounty programs and top ranking on both Anthropic’s Safety Bug Bounty Program on HackerOne and Mozilla’s 0din GenAI Bug Bounty Program. His work targets prompt injection, data exfiltration, and AI agent security.