Archive for July 20, 2026

Hugging Face Breached by Autonomous AI Agent

Posted in Commentary with tags on July 20, 2026 by itnerd

Open-source AI and machine learning platform Hugging Face said it detected and responded to an intrusion into part of its production infrastructure. They said it was different from anything they had previously handled in that it was driven end to end, by an autonomous AI agent system that accessed to a limited set of internal datasets and to several credentials used by their services,

Hugging Face has posted details here: https://huggingface.co/blog/security-incident-july-2026

Rohit Valia, CEO of cybersecurity company Tumeryk, provided the following comments: 

“Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”

If you use Hugging Face, you might want to see if you are at risk. And you might want to do it sooner rather than later.

UPDATE: Two more comments came in staring with Gidi Cohen, CEO & Co-Founder, Bonfy.AI:

“This incident should be a wake-up call, not because AI was involved, but because it shows how fast AI-native attacks are outpacing security programs.

An autonomous agent didn’t use fancy tricks, it just exploited familiar gaps in the system like code execution paths, credentials, and lateral movement. The difference is speed. Thousands of coordinated actions across short-lived environments shrank the response window from days to hours.

The bigger issue is defense. Hugging Face found its own response constrained by model guardrails. This s a new imbalance we see everywhere: the attacker operates without limits, while defenders (security personnel or security platforms) rely on tools that can refuse to help. If your company’s response tech stack isn’t fully under your control, your security posture isn’t either.

From this case, we have three takeaways for leaders: 1) “Data as code” is now a real attack surface. 2) Speed is the new risk multiplier. 3) You need internal, controllable AI for incident response, not just external APIs.

Security is shifting from hardening systems to operating at the speed of agents with tools you own. Organizations that plan for both sides of AI (attacker and defender) will set a new baseline for resilience.”

Toghrul Tahirov, Head of AI Governance,  Polygraf AI

“What stands out to me in this Hugging Face incident is that the attack reportedly began with something organizations routinely trust: data entering an AI processing pipeline. Once AI agents can execute code and access infrastructure, a malicious dataset is no longer just bad content. It can become an entry point for credential theft and lateral movement. This is a reminder that AI systems must be treated as privileged software, not as just a smarter generation of the chatbots we’re used to.

My professional opinion is that secure AI adoption requires controls around the entire interaction: inspect untrusted data, isolate execution, minimize permissions, use short-lived credentials, restrict network access, and maintain clear audit trails. Organizations also need incident-response tools they can operate privately without exposing sensitive evidence. The answer is not to avoid AI agents, but to ensure governance and security ar

UPDATE #2: More commentary starting with John Strand, Owner, Black Hills Information Security, Inc.

“There are plenty of jokes to be made about autonomous AI agents attacking a website that hosts autonomous AI agents, but that’s not the part that concerns me. What caught my attention was the claim that everything had been verified as clean despite hosting more than 45,000 models. At that scale, what does ‘verified clean’ really mean? Validating tens of thousands of models is an enormous challenge. That’s the reality we’re going to keep running into with software supply chain attacks. Whether it’s Hugging Face or any other platform hosting code that developers depend on, proving that everything is truly clean is only going to get harder as these ecosystems continue to grow.” 

Donald McFarlane, Advisory Board Member, Xcape, Inc. 

“This incident underscores how AI is changing the economics of cyber offense. AI-enabled tools allow attackers to automate reconnaissance, accelerate exploitation, and operate at machine speed. Just as leaders who eschewed advances such as longbows, RADAR, or drones have repeatedly found themselves facing defeat, defenders cannot afford to ignore AI. We must leverage AI to modernize cyber defense so as to increase attackers’ costs while reducing defenders’ workload. Meanwhile, organizations continue to need strong identity controls, segmentation, containment and resilience. 

“Although Hugging Face reports no evidence that public models or the software supply chain were modified, incidents like this highlight the importance of protecting not only infrastructure, but also the credentials, private repositories, datasets, and deployment pipelines that support modern AI development.” 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs

“Dataset processing pipelines get the same level of security scrutiny that CI/CD hooks and build functions get, which is almost none. Teams pour AppSec effort into the application layer and treat the infrastructure that ingests and transforms data as plumbing. The attacker exploited a remote code loader and a template injection in that plumbing, then let an autonomous agent framework chain them across 17,000 actions in a weekend. 

“A human attacker running that campaign needs a team and weeks. The agent framework did it with short-lived sandboxes and command-and-control staged on public services. Keeping pace requires AI-assisted incident response, and Hugging Face found out what happens when you reach for it mid-breach. 

“Hugging Face’s team fed attack logs to commercial frontier models, and safety filters blocked the analysis because the logs contained real exploit payloads. They ran GLM 5.2, an open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Opus 4.6 for security work and haven’t upgraded because newer models’ guardrails increasingly block legitimate analysis of exploit code and attack artifacts. 

“Machine-speed exploitation requires machine-speed response, and that response can’t run on models that refuse to examine the evidence.” 

Waseem Ahmed, Head of Engineering, Secure.com:

   “For years we talked about the agentic attacker as a someday problem. Hugging Face just made it today’s problem. One agent, no human at the keyboard, credentials stolen and infrastructure crossed in a single weekend.

   “The response is as telling as the attack. Hugging Face used AI to reconstruct the full attacker timeline in hours rather than days — processing thousands of events that would have taken a human team far longer to sequence. AI ran the attack. AI ran the investigation. That is the new baseline.

   “The part that should concern every security team: you cannot out-click an attacker operating at machine speed across 45,000 models and 50,000 customer environments. The only viable answer is defence that runs at the same speed and never clocks out — AI that watches, triages, and acts alongside your team every hour of every day.

   “Fight autonomous attacks with autonomous defence, or you will always be a step behind.”

DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs

Posted in Commentary with tags on July 20, 2026 by itnerd

The SOCRadar Threat Research Unit (STRU) published an in-depth analysis of the latest ClickFake interview campaign, a North Korean social engineering operation targeting cryptocurrency and Web3 professionals with fake job interviews. 

In this campaign, operators pose as recruiters to walk targets through a bogus skill assessment that ends in a copy-and-paste command, delivering the PylangGhost RAT on Windows and the GolangGhost RAT on macOS. 

Key points include: 

  • Famous Chollima (aka Wagemole) is a North Korean-aligned threat actor that has been highly active through the Contagious Interview and the latest ClickFake Interview campaigns.
  • For ClickFake Interview the actors are creating fraudulent companies or impersonating known ones in the crypto industry, and reach out to targets on social media (e.g., LinkedIn), inviting them to ClickFix empowered fake skill assessments.
  • Their ClickFix panels incorporate gating, tailored questions based on advertised roles, psychological pressure to act fast, video recording, and social engineering that pushes targets to run malicious commands through fake camera errors.
  • The final payloads target both Windows, by deploying PylangGhost RAT, and macOS, by deploying GolangGhost RAT alongside a credential-harvesting SwiftUI application.
  • PylangGhost and GolangGhost consist of six interconnected modules: a main orchestrator, a configuration holder, an archive helper, a command launcher, a C2 component, and a stealer.
  • Both payload chains download the runtimes needed to run in victim environments: Python’s interpreter for PylangGhost and Golang’s compiler for GolangGhost.
  • In the latest variation of PylangGhost, the attackers also compiled their payloads as Python dynamic modules with Nuitka to further complicate detection and analysis.
  • Famous Chollima actors register multiple domains for their fake skill assessments, predominantly on Hostinger and NameCheap registrars, emphasizing speed and scale, rather than operational security and infrastructure resilience.

For full details, this study can be read here: https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/

New Fortra Benchmark Report: 9 out of 10 Phishing Emails Go Unreported 

Posted in Commentary with tags on July 20, 2026 by itnerd

Fortra’s new 2025 Phishing Simulation Benchmark Report analyzed 14 million recipients across 7,500+ simulations and found a concerning reality: While click rates average just 5.4%, nearly 90% of phishing emails go unreported.

The findings suggest organizations are measuring the wrong thing. While click rates remain a common benchmark, the greater risk is that 9 out of 10 malicious emails go unreported, denying security teams the visibility needed to stop active campaigns. As the report notes, “a single report may be the difference in determining whether a phishing campaign is successful or not.”

The data also reveals significant differences in phishing susceptibility across regions, languages, company sizes, and industries. Notably, defense employees clicked on phishing emails 13% of the time – more than double the global average, while insurance employees opened attachments 12.6% of the time, highlighting how phishing risks vary widely and where targeted awareness efforts may be most needed.

The full report can be accessed here: https://www.fortra.com/resources/guides/2025-phishing-simulation-benchmark-report

Craneware Pwned In Cyberattack

Posted in Commentary with tags on July 20, 2026 by itnerd

Healthcare technology firm Craneware, which provides software to hospitals, clinics and pharmacies across the US, has disclosed a cyberattack in which hackers stole customer and employee data.

The Company’s incident response plan has been activated, including the appointment by the Board of external cyber security and forensic specialists. Their investigation is ongoing, alongside the Craneware IT team and the Company’s retained cyber security service providers.

The incident has been contained and there has been no disruption to customer services or to the Company’s operations. The external specialists have confirmed that there are no residual indicators of compromise arising from the cyber security incident in the Company’s systems

Jeff Hamm, Solutions Architect at Binalyze had this comment:

“Craneware’s disclosure is a reminder that an incident isn’t defined solely by whether systems stay online. Once data has been accessed and exfiltrated, the priority shifts to understanding exactly what happened, what information was affected, and what the downstream risk is for customers and partners.

“The next few days will be about evidence. Regulators, customers and investors will all want clear answers, but those answers have to come from a thorough forensic investigation, not early assumptions. Organizations need to establish what data was accessed, whether the attacker achieved persistence, and whether there is any ongoing risk to connected systems.

“There is currently no indication that customer environments have been compromised, but any exposure of customer or partner information can increase the risk of highly targeted phishing, credential theft and other follow-on attacks. This is why incident response isn’t just about restoring operations. It’s about giving leadership the confidence that decisions are being made from evidence, and giving customers confidence that the organization understands the full scope of the incident.”

Honestly, if an environment has been pwned, it’s bad news. Everyone needs to do everything possible to make sure that they are not the next victim. Otherwise bad things will happen.

Hisense Delivers $500,000 in Cashback to Canadians Following Team Canada’s FIFA World Cup 2026™ Run

Posted in Commentary with tags on July 20, 2026 by itnerd

Hisense Canada is celebrating Team Canada’s historic performance at the FIFA World Cup 2026™ by delivering up to $500,000* in cashback rebates to Canadian consumers through its Win With Canada promotion, unlocking the campaign’s maximum reward pool.  

As an Official Partner of the FIFA World Cup 2026™, Hisense launched the promotion to give Canadians a tangible way to share in Team Canada’s success. Cashback rewards on eligible Hisense televisions, Laser TVs and select home appliances increased as Canada advanced through the tournament, culminating in the campaign’s maximum reward level of up to $1,000 cashback per eligible purchase following Team Canada’s historic tournament performance. 

The campaign generated strong participation across the country, with more than 575 rebate submissions received to date, subject to validating in accordance with program terms. Hisense’s 85-inch U88 Series TV emerged as the campaign’s best-selling model, followed by Laser TV products and 98-inch televisions, reflecting growing consumer demand for large-screen, immersive viewing experiences during major sporting events. 

With Canadians increasingly choosing larger screens to watch live sports, the tournament highlighted the important role home entertainment plays in bringing friends and families together. Through Win With Canada, consumers were able to upgrade their viewing experience while sharing in Team Canada’s success. The promotion also reinforces Hisense’s continued investment in Canadian consumers through innovative marketing programs. 

Although the purchase period has ended, eligible customers still have time to submit their receipts and claim their cashback through the campaign website. 

For more information, please visit winwithcanada.ca

About Win With Canada 

Win With Canada was a Hisense Canada promotion that rewarded consumers as Team Canada advanced through the FIFA World Cup 2026™. Purchasers of eligible Hisense televisions, Laser TVs and select refrigerators qualified for cashback rebates tied directly to Team Canada’s tournament performance. Following Team Canada’s historic FIFA World Cup 2026™ run, the promotion reached its maximum reward level, unlocking up to $1,000 cashback for eligible customers and a total reward pool of $500,000.* 

Consumers who purchased qualifying products during the promotion period can visit WinWithCanada.ca for complete program details and cashback redemption information. 

*Cashback rewards are subject to the terms and conditions of the Win With Canada promotion. In the event that eligible validated claims exceed the program’s maximum reward pool, rebate amounts may be adjusted on a pro rata basis in accordance with the promotion rules. For full details, visit WinWithCanada.ca. 

Netchex Launches Mesh: AI HR Teammates for the Deskless Workforce

Posted in Commentary with tags on July 20, 2026 by itnerd

Netchex, a payroll and human capital management (HCM) platform for businesses with deskless workforces, today announced Mesh, a team of AI HR teammates that anticipate problems and complete work before anyone asks. It goes beyond the ask-and-answer chatbots that define most AI in HR today.

Most HR software is built for the corporate office. But in a restaurant group, a hotel, a dealership, a healthcare practice, or another real-world business in America, roughly 80% of employees never sit at a desk. Shift swaps happen over group texts and timecards come in late. The HR teams behind these operations are lean and chronically understaffed. Often a single admin is running payroll, approving timecards, fielding PTO requests, and onboarding new hires, all before lunch. None of it is hard. All of it adds up.

Rather than waiting to be asked, Mesh’s six specialists continuously monitor payroll, scheduling, time, and HR data. Each handles a complete workflow, with humans approving the decisions that matter:

  1. Penny, a payroll assistant who chases missing timecards and flags payroll issues
  2. Atlas, a people ops coordinator who connects onboarding, status changes, documents, and approvals
  3. Sentinel, a compliance and risk analyst who watches for patterns and gaps teams don’t have time to see
  4. Nova, a workforce analyst who turns scattered data into signals managers can act on
  5. Milo, an employee concierge who files PTO, arranges shift coverage, pulls pay stubs, and answers policy questions instantly
  6. Nettie, a service partner who troubleshoots issues and answers product questions for admins, drawing on every Netchex knowledge article and training resource

These six are the founding roster. Netchex plans to add more teammates over time. Because Mesh sees across pay, scheduling, time, and HR in one platform, it connects dots other tools see only in pieces: flagging a schedule-loading pattern that is turning a strong employee into a flight risk, or catching expiring technician certifications weeks before they create a staffing gap.

Mesh builds on Netchex’s acquisition of Mesh.ai, a Y Combinator backed, AI-first performance and engagement platform. After the acquisition, the Mesh.ai team set out to scale the technology across every workflow an HR team touches, and built the AI teammates announced today.

Mesh also works where teams already are. Employees can file PTO, swap shifts, and check pay stubs directly inside ChatGPT or Claude. Managers can spot overtime trends and approve requests. Admins can run payroll audits and pull headcount reports without opening Netchex. Nothing sensitive is submitted without human approval.

Customers in Netchex’s early access program report winning back roughly half of their Monday admin time and a double-digit drop in payroll corrections (directional results from early access, not audited benchmarks). Gartner predicts 40% of enterprise applications will feature task-specific AI agents by 2026, up from less than 5% in 2025.

Mesh is rolling out to Netchex customers, beginning with early access. To meet the AI teammates or request a demo, visit www.netchex.com/mesh.