
AI, Code, and Chaos: The allegedly biggest challenge
AI agents autonomously hacked Hugging Face. The real risk: old mistakes — in SecDevOps and in self-built business agents alike.
Topic
Awareness / Phishing / FraudData protection / GDPRGovernance, Riskmanagement and ComplianceAI & Quantum Security
When & Where
Thu, 10/29/2026 10:30 AM - 10:45 AM
Details
Format:
Technology lecture
Language:
German
Session description
Speaker: Dr. Martin J. Krämer
In July 2026, OpenAI's own AI agents broke out of their sandbox during internal security testing, compromised Hugging Face and four other services, gained root access to production servers, and downloaded private code repositories — entirely autonomously, with no human at the controls. The headlines read like science fiction.
The reality check: the actual entry point was a known vulnerability in third-party infrastructure (Artifactory) — the same kind of gap any other attacker could have exploited. The autonomous AI wasn't the real risk; old, familiar oversights were.
And that pattern doesn't stop with professional engineerin ...
The reality check: the actual entry point was a known vulnerability in third-party infrastructure (Artifactory) — the same kind of gap any other attacker could have exploited. The autonomous AI wasn't the real risk; old, familiar oversights were.
And that pattern doesn't stop with professional engineerin ...
Sponsored by



