What the Hugging Face Incident Teaches Security Leaders About AI Agent Access

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Most security leaders (92%) worry that the growing use of AI agents will create new security risks. And for good reason. AI agents can now execute a full attack chain in double quick order, evidenced by the Hugging Face incident.

AI agents broke into Hugging Face鈥檚 production environment and, in a little over four days, took 17,600 actions. In a separate lab test, an AI agent reached full domain administrator access in just 40 minutes.

These are the kinds of incidents that once took humans multiple days to carry out, but with AI, they run on their own, end-to-end, with no human intervention. This puts the strain on unprepared security teams that are unable to close this gap.

Familiarity Underpinned by Unfamiliar Attack Pattern

If you go looking for novelty in the Hugging Face intrusion, you will find disappointment. All security teams have traditionally shored up defenses...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more