After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government
FedRAMP Director Pete Waterman speaks at Carahsofts FedRAMP Summit on July 23, 2026. Frank Konkel / Government Executive
ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW
July 23, 2026 02:32 PM ET
Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.
Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, the head of the government’s bedrock cloud security program said Thursday.
Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program, known as FedRAMP, delivered the blunt warning while discussing resistance from companies that say they lack the resources to address a known, exploitable vulnerability exposed to the internet within a matter of days.
“If that is the way...
Copyright of this story solely belongs to nextgov.com. To see the full text click HERE