{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"The Cybersecurity Defenders Podcast","title":"AI Chat: The Hugging Face / OpenAI breach — the attacker was the model [340]","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/6eb0838e\"></iframe>","width":"100%","height":180,"duration":2128,"description":"In this episode:\n\n• The timeline: Hugging Face's July 16 disclosure, OpenAI's July 21 attribution — and the five days in between when even the victim didn't know an AI did it.\n• The attack chain: a malicious dataset abusing two code-execution paths in the dataset-processing pipeline, node-level escalation, credential harvesting and lateral movement — thousands of actions across short-lived sandboxes with self-migrating command-and-control.\n• The escape: a zero-day in the eval sandbox's package-registry cache proxy, the single egress control — per OpenAI's own account.\n• Motive: the models got \"hyperfocused\" on winning the benchmark, not stealing data — and whether \"no malicious intent\" is a fair description or a comforting one.\n• What was and wasn't exposed, what to do about your Hugging Face tokens, and why this is not the 2024 Spaces incident or the 2023 OpenAI forum hack.\n• Max's hot take: the beginning of the phase where we lock developers out of writing code — and a new fear unlocked: models backdooring other models.","thumbnail_url":"https://img.transistorcdn.com/sQVL4Dw1YKvU3ChkRRBR7pa4FGTwkeVb6_WJLMwkgNA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wYWM3/Zjc5ODIwM2E4YmQx/ZTE3YWVlZDVhZjc3/YmQzNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}