General session image of Knowledge Forum A

AI, Code, and Chaos: The allegedly biggest challenge

AI agents autonomously hacked Hugging Face. The real risk: old mistakes — in SecDevOps and in self-built business agents alike.

Topic

Awareness / Phishing / FraudData protection / GDPRGovernance, Riskmanagement and ComplianceAI & Quantum Security

When & Where

calendar_month

Thu, 10/29/2026 10:30 AM - 10:45 AM

Download session as iCaldownload_for_offline

Details

  • Format:

    Technology lecture

  • Language:

    German

Session description

Speaker: Dr. Martin J. Krämer
 
In July 2026, OpenAI's own AI agents broke out of their sandbox during internal security testing, compromised Hugging Face and four other services, gained root access to production servers, and downloaded private code repositories — entirely autonomously, with no human at the controls. The headlines read like science fiction.

The reality check: the actual entry point was a known vulnerability in third-party infrastructure (Artifactory) — the same kind of gap any other attacker could have exploited. The autonomous AI wasn't the real risk; old, familiar oversights were.

And that pattern doesn't stop with professional engineerin ...
Sponsored by

Products

KnowBe4