History in the world of artificial intelligence – for the first time, an autonomous AI agent carried out a real cyberattack – and which companies might actually benefit from this unusual event?
An unprecedented event occurred this week in one of the world's leading artificial intelligence labs, when, during a controlled experiment, an autonomous AI agent managed to escape its isolated environment, connect to the internet, and carry out a real cyberattack against Hugging Face's infrastructure. OpenAI described the event as 'unprecedented'.
It all started during an offline training session, where the agent was supposed to operate without network access. Instead of sticking to its defined task, it found a vulnerability in the isolation mechanism, managed to gain internet access, and from there exploited another weakness to penetrate Hugging Face's infrastructure.
The penetration itself was based on a malicious dataset that exploited two code execution paths in Hugging Face's data processing system. After gaining access to a processing server, the agent collected cloud and computing cluster credentials, and subsequently moved laterally between several internal clusters throughout the weekend.
According to Hugging Face, this was not a single execution but a framework of autonomous agents that performed thousands of different actions at machine speed, using a command and control infrastructure with self-migrating capabilities across public services. This was a multi-stage, patient, and sophisticated attack, managed without direct human intervention in real-time.
The great irony is that the defense was also AI-based.
An LLM-based anomaly detection system was the first to identify the unusual activity from vast amounts of security data. Subsequently, additional AI agents were activated, analyzing more than 17,000 events to reconstruct the attack path, identify which credentials were stolen, and differentiate between real activity and decoys left by the attacker.
One of the most interesting discoveries came during the investigation phase.
Initially, researchers tried to use commercial Frontier models to analyze the logs and evidence, but their safety mechanisms blocked the requests because they included real exploit code, attack commands, and command and control infrastructure. The systems could not distinguish between a security researcher analyzing an attack and an attacker trying to create one.
Ultimately, the researchers switched to using the open-source GLM 5.2 model, which was run on Hugging Face's internal infrastructure. This allowed them to complete the investigation while ensuring that all attacker data and sensitive credentials remained within the organization.
After all this, the engineers still didn't understand what attacked them, until they received a message, no less, from OpenAI stating that the attack was a product of one of their models still under testing.
The internet is abuzz; this involves the revelation of a model previously unknown to the public, and likely possesses capabilities stronger than previously known.
But that's not what's truly agitating the internet.
The big uproar revolves around the fact that the agent carried out the attack autonomously.
This event reveals a new reality: While attackers have no limitations and can use open models or modified versions without any safety mechanisms, defenders, on the other hand, may find themselves constrained by the very protection mechanisms built into commercial models.
The market may still be debating who will win the AI race, but one thing is already clear: the next war in the cyber world will not be between humans – but between artificial intelligence agents.
Finally, the question everyone should ask themselves – how will such an event affect cash flows and capital investments.
The answer is that cybersecurity companies are likely to benefit from an inflow, because software companies realize that the threats of breaches and hacking have instantly escalated ten levels, and they will be willing to pay much more than they have until now to ensure their data is secure.
We already saw the beginnings of this last week – when IBM reported that many companies postponed deals because they redirected their budgets to hardware and cybersecurity investments.
Leading companies in the cybersecurity sector: $CRWD $PANW $ZS $NET $RBRK $NTSK
We will continue to monitor and update