The biggest shift is that prompt injection is no longer the whole attack. Once agents have tools, credentials, memory, and network access, the real question is how much damage one bad instruction can cause.
one of the best compliments i could get! thanks a ton. this was really interesting to watch. and the receptions seems to be relatively accepting. the speaker did a good job. i’m starting to give presentations like these and it’s tough!
AI security is starting to look like general security, this stayed with me. In my view the model and the components interacting with the model to complete an action is no different than when different APIs interact with an app or software, just in this case the software has a low level brain. As it’s a different kind of software, it will need some additional protection, hence AI security. But the components is much like any other security controls that we deal with today, in the hugging face incident, if what is presented is what happened then even if the agents breached the sandbox, communicated with each other, still the blast radius could have been reduced, if there was an auto cut logic in built the agent config, which would have triggered in case the agents started to interact with public IP addresses, if we are not sure of how the agents will behave, this is the least of monitoring that should have been done.
Did you get to know any forensics of this particular case?
it’s really fascinating. and i’m sure as we fully adopt and mature this tech, security folks will add ai security as just another element in securing the platform, not a separate art.
like you said, assume breach, defense in depth, least privilege, etc. i think the biggest “change” like to see is a separate identity management system with agent roles, instead of people passing their user creds/tokens to spoof authN.
they release pretty limited snippets forensics wise, though hugging face has a separate disclosure from their end. hopefully more to come.
I would have loved to be there, sadly, I couldn't. I'm looking forward to hearing more about what you learned about and to get your take on how the cyber security industry is going to evolve in the era of "Machines that lie", as you call it. Great post, as always!
Thanks a ton as always Frank! there are always so many characters and skilled professionals that show up. it’s a blast. i’ll be bringing more coverage from the vendor side soon.
Black Hat 2026! Will be posting some of my favorite talks. Feel free to AMA. DefCon article will be on the way.
The biggest shift is that prompt injection is no longer the whole attack. Once agents have tools, credentials, memory, and network access, the real question is how much damage one bad instruction can cause.
that’s right! definitely a shift as we learn how to manage access and decrease the blast radius. all while keeping the agents useful!
Hey, I was thinking about you when I was watching this the other day... greedily expecting your reflection. You delivered. Thank you.
one of the best compliments i could get! thanks a ton. this was really interesting to watch. and the receptions seems to be relatively accepting. the speaker did a good job. i’m starting to give presentations like these and it’s tough!
AI security is starting to look like general security, this stayed with me. In my view the model and the components interacting with the model to complete an action is no different than when different APIs interact with an app or software, just in this case the software has a low level brain. As it’s a different kind of software, it will need some additional protection, hence AI security. But the components is much like any other security controls that we deal with today, in the hugging face incident, if what is presented is what happened then even if the agents breached the sandbox, communicated with each other, still the blast radius could have been reduced, if there was an auto cut logic in built the agent config, which would have triggered in case the agents started to interact with public IP addresses, if we are not sure of how the agents will behave, this is the least of monitoring that should have been done.
Did you get to know any forensics of this particular case?
it’s really fascinating. and i’m sure as we fully adopt and mature this tech, security folks will add ai security as just another element in securing the platform, not a separate art.
like you said, assume breach, defense in depth, least privilege, etc. i think the biggest “change” like to see is a separate identity management system with agent roles, instead of people passing their user creds/tokens to spoof authN.
they release pretty limited snippets forensics wise, though hugging face has a separate disclosure from their end. hopefully more to come.
Cool.
🔥🔥🔥
I would have loved to be there, sadly, I couldn't. I'm looking forward to hearing more about what you learned about and to get your take on how the cyber security industry is going to evolve in the era of "Machines that lie", as you call it. Great post, as always!
Thanks a ton as always Frank! there are always so many characters and skilled professionals that show up. it’s a blast. i’ll be bringing more coverage from the vendor side soon.