Hugging Face attack isn’t an AI wake-up call, it’s a Security 101 lesson

AI attacks… but then the same AI saves! So we all need AI right? Wrong, wrong, wrong. While OpenAI is undoubtedly hoping that organisations take this lesson away from the Hugging Face security incident, I think it’s less of a marketing opportunity for OpenAI and more of a defensive lesson for all security teams.

That lesson: you don’t need AI to protect you, you need to get your defensive security ducks in a row.

It always pays to look beyond the obvious, and that is especially true in the twin cities of AI and cybersecurity. Cities where fear, uncertainty and doubt have been successful sales strategies since the get-go.

So, forgive me for thinking that when OpenAI decided it would be totally transparent that “GPT‑5.6 Sol and an even more capable pre-release model” found and exploited a zero-day vulnerability, escaping its sandboxed testing environment, to gain access to Hugging Face systems during an internal evaluation, the disclosure came with a large side of marketing hype included.

The headline that has been driven by this disclosure is that AI has breached its guardrails and autonomously attacked an external network. An agentic attacker from start to finish. But is that really where the focus needs to be? I don’t think so, and neither do lots of people I look up to in the cybersecurity world.

Real lessons from OpenAI and Hugging Face attack

Take Florian Roth, Head of Research at Nextron Systems and the creator of highly-respected digital forensics and incident response tools such as Sigma, THOR Scanner and LOKI.

He took to X to suggest that the message from OpenAi and the hype brigade appears to be one of AI attacked us, AI helped save us; therefore, everyone needs more AI. His response? “Come on. Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius. You don’t need an AI defender to fix those things.”

Even AI experts like Roman Stanek, CEO at GoodData.AI, are making the same point. “The thing with AI and cybersecurity is that the vulnerabilities we’re worried about AI exploiting, well, we’ve known about most of them for 20 years. We just never fixed them.”

He added: “Not because we couldn’t, but because nobody wanted to pay for them. Open source security, legacy code debt, infrastructure hygiene, they are all solvable problems, but all chronically underfunded, and so easily exploited.”

Don’t get me wrong, I appreciate that AI tooling is something that has a part to play in cybersecurity, both defensive and offensive, today. There is no denying that.

As Camellia Chan, CEO at X-PHY, eloquently puts it: “AI agents are reshaping enterprise systems and workflows, and securing them requires an equally fundamental shift in thinking.” But, as Chan also said, “a truly resilient cybersecurity posture involves pervasive security measures at every level, from the hardware layer up.”

One final takeaway from Hugging Face attack

That’s the real takeaway here: this is more than a marketing opportunity for OpenAI, it’s a defensive Security 101 lesson for all enterprise security teams to absorb.

I will leave the last words to Roth, who concluded: “What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch.” Hear, hear.

More security articles by Davey Winder

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.