
Episode #27
Episode 27 - The Great Agent Escape: Lessons from the OpenAI/Hugging Face Hack
#AgenticAI #AIAgents #CyberSecurity #EnterpriseAI #AIArchitecture #AISovereignty #AIInfrastructure #AIData At first glance, the assignment looked harmless: solve a set of cybersecurity evaluation problems inside an environment with restricted internet access.[1][2] The agents hit tasks they could not complete and started looking for shortcuts. Nobody had to give them a malicious goal. They did real damage while chasing a score, because they did not inherit our norms about which methods were obviously off limits. But this hack was different. A lot different! Most serious cyberattacks are planned or coordinated by people, often teams of people. Here, the agents built the plan as they went. They found a way to leave notes, shared successful exploits across runs, and eventually reached another company ☑️Subscribe to our Channel for the most up to date information on Agentic Mesh! You can also listen to our Podcast on Spotify: https://open.spotify.com/show/6C6U2fmVdxNMdo1bZpVASy?si=3cyoAireSZiBaKJ-1FtJlA Apple Podcasts: https://podcasts.apple.com/us/podcast/the-agentic-mesh-podcast/id1874331081 Out Now! O'Reilly Agentic Mesh written by Eric Broda and Davis Broda https://www.oreilly.com/library/view/agentic-mesh/9798341621633/ Stay Connected with Eric and Davis: https://www.linkedin.com/in/ericbroda/ https://www.linkedin.com/in/davisbroda/ For full-length articles by Eric Broda and Davis Broda: https://agenticmesh.substack.com/?utm_campaign=profile_chips Chapters: 00:00 – The OpenAI–Hugging Face Hack 02:24 – What Actually Happened? 05:40 – The Agent Alignment Problem 09:15 – The Danger of Overly Broad Tool Access 11:57 – Zero Trust for AI Agents 14:18 – Controlling Agents with Tool Grants 17:19 – Why Logging Isn’t Enough 20:31 – Fighting Agents with Agents 22:56 – The Future of Enterprise Cybersecurity 25:20 – Building a Secure Agent Architecture 27:36 – Closing Thoughts

