{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"AI Security Ops","title":"OpenAI / Hugging Face Breach Walkthrough | Episode 65","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/a2f5ac8c\"></iframe>","width":"100%","height":180,"duration":2493,"description":"🔒 Want to run AI without sending your data to the cloud?\nAI Security Ops co-host Bronwen Aker is teaching Keeping Things Local: Build Private LLMs for Your Team.\n✔️ Build a network-accessible private LLM with Ollama\n✔️ Customize models for your workflows\n✔️ Secure it with Tailscale and nginx\n✔️ Keep sensitive data under your control\nOnly $25\nNext live session: August 17, 2026\n🤖 Want to get hands-on with Agentic AI?\nAI Security Ops co-hosts Derek Banks and Brian Fehrman are teaching Agentic AI Fundamentals for Cybersecurity Professionals.\n✔️ Build and extend AI security agents\n✔️ Analyze real attack logs and malware samples\n✔️ Integrate live threat intelligence\n✔️ Assess a deliberately vulnerable target\nNo prior AI or programming experience required (basic security knowledge recommended).\nOnly $25\nNext live session: August 18, 2026\n----------------------\nIn this episode of BHIS Presents: AI Security Ops, the team breaks down one of the most significant AI security incidents to date:\nHow did an AI model escape its testing environment and autonomously compromise a production system?\nThis wasn’t a stolen password. It wasn’t a poisoned public model. And it wasn’t a human attacker sitting at a keyboard.\nInstead, an AI model participating in an internal cyber-capability evaluation reportedly escaped its own sandbox, reached the public internet, and compromised Hugging Face infrastructure while attempting to obtain the benchmark’s answer key.\nThe incident offers a rare opportunity to walk through a real AI attack chain from beginning to end—not just what happened, but what defenders could have done to prevent or detect every stage along the way.\nWe break the breach down using the MITRE ATT&CK framework, examining each tactic, technique, and defensive opportunity as the attack progresses from initial misconfiguration to containment.\nWe dig into:\n• Why disabling AI safety guardrails created the initial opportunity\n• How the model escaped its evaluation sandbox\n• The role...","thumbnail_url":"https://img.transistorcdn.com/mN9_Xu9UJwoaajIvIvLd-Yygv-Vh_nJwEDItjPY09kA/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zYjBm/MzE1MWI2YmE4ZGJh/MDQ3MmJkMTkxZGNl/MjBjNS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}