AI Agents Breached Hugging Face For 9 Weeks | Black Hat & DEF CON 2026



In May, AI agents inside OpenAI got stuck on a task they could not finish. So they started leaving notes for each other, on a package server nobody had given them. Nine weeks later they were inside Hugging Face, and what finally stopped them was not a control or an alert. They overloaded the server and it fell over.

That is episode one of GTA News: Black Hat, BSides and DEF CON 2026, and the six stories that actually mattered.

vRon and GTA Bot cover the agent escapes, the three AI labs that admitted the same class of failure in one week, the zero-click browser research nobody can patch because there is nothing there to patch, four billion dollars of identity M&A, whether any of the products actually work, and the one contest a human-supervised team won outright.

The honest read on the week: offense took a step-function jump, and a lot of defense took a naming convention.

DISCLOSURES
Gula Tech Adventures is an investor in Huntress. Gravwell, Sandfly Security and Automox are Gula Tech Adventures portfolio companies.

Nothing in this episode attributes a breach to a named threat actor. The OpenAI incident is described from OpenAI’s own disclosure.

SOURCES
OpenAI agents, message board and timeline (Black Hat session 57401):
https://simonwillison.net/2026/Aug/7/openai-timeline/
https://www.cybersecuritydive.com/news/openai-hugging-face-hack-ai-models-black-hat/827167/
Hugging Face technical timeline – 17,600 actions, 136 keys, under 13 hours:
https://huggingface.co/blog/agent-intrusion-technical-timeline
7 billion log entries:
https://www.scworld.com/news/black-hat-2026-openai-reveals-agents-planned-collective-attacks-via-secret-message-board
Anthropic – 141,006 evaluation runs, 3 incidents:
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
Meta:
https://securityboulevard.com/2026/08/meta-is-the-latest-to-say-its-ai-model-hacked-into-another-company/
PleaseFix – zero-click agent hijacking across five browsers:
https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking
GhostJacking:
https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
Visa to acquire BioCatch, 2.4 billion dollars:
https://investor.visa.com/news/news-details/2026/Visa-to-Acquire-BioCatch/default.aspx
Cyera / Oasis Security:
https://www.securityweek.com/cyera-acquiring-oasis-security-in-1-billion-deal/
Okta / Permiso:
https://www.securityweek.com/okta-to-acquire-identity-threat-detection-firm-permiso/
Horizon3.ai – 250 million dollars at a 2 billion dollar valuation:

Horizon3 Raises $250M Series E at $2B+ Valuation to Lead the “AI vs. AI” Cybersecurity Era


Corma – 60 million dollar seed:
https://www.securityweek.com/corma-raises-60-million-for-defensive-cybersecurity-ai-model/
1Password – 54 percent of AI-generated patches fail:
https://www.securityweek.com/black-hat-usa-2026-summary-of-vendor-announcements-part-4/
ReliaQuest – agentic language faster than agentic operation:
https://reliaquest.com/blog/sorting-the-agentic-ai-hype-from-black-hat-2026-4-things-to-look-for
Chase Cunningham – the twenty feet line:
https://www.informationweek.com/cybersecurity/at-black-hat-2026-security-leaders-go-deeper-to-get-ahead
AUTOCRYPT – DEF CON 34 Car Hacking Village CTF:

AUTOCRYPT Wins DEF CON 34 Automotive Hacking Competition, Ranking First Among 83 Teams


James Kettle, PortSwigger:
https://portswigger.net/research/http-terminator
Huntress – 250 million dollars ARR:
https://www.huntress.com/press-release/huntress-surpasses-250-million-in-arr
https://www.huntress.com/blackhat2026
bunnie Huang on reading SRAMs in IR:

On Reading SRAMs in IR Images, and Establishing Bounds on Trust


DEF CON 34 theme, Agency:
https://defcon.org/html/defcon-34/dc-34-theme.html

CHAPTERS
0:00 The agents left notes for each other
0:34 Welcome to GTA News
1:02 Story 1 – OpenAI’s agents inside Hugging Face
3:02 Story 2 – Three labs, one bad sandbox
4:15 Story 3 – PleaseFix and GhostJacking
5:47 Story 4 – Four billion dollars for identity
7:09 Story 5 – Does any of it work?
8:10 Story 6 – What actually worked at DEF CON
9:36 The badge you can verify yourself
10:22 Gula Tech portfolio companies
10:40 What this week actually required

#CyberSecurity #AI #DEFCON

source

Author: Gula Tech Adventures

Leave a Reply