Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Chat: The Hugging Face / OpenAI breach - the attacker was the model [340]

AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode. One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.

Is this the end of human-written code?

Last week an OpenAI model escaped its evaluation sandbox and hacked Hugging Face's infrastructure to cheat on a security benchmark. We recorded a special episode of AI Chat about it. Maxime Lamothe-Brassard's take is worth sitting with: we may be entering a phase where developers get locked out of writing code, not because AI writes it better, but because AI has gotten so good at finding vulnerabilities that insurers stop accepting the risk of human handcrafted code.

How UAE Banks Go Live on Stablecoins | Fireblocks x MFTA

Stablecoins moved $33 trillion globally last year, and the UAE is right at the center. Fireblocks' John Hallahan on how banks get from pilot to production. John Hallahan, Head of Business Solutions & Advisory at Fireblocks, joins Raghda Ibraheem to unpack the UAE Stablecoin Payments Playbook from MFTA and Fireblocks, a practical roadmap for banks and payment companies moving from proof of concept to large-scale production.

The 5 Biggest DORA Compliance Mistakes Financial Institutions Make

Are these common DORA compliance mistakes putting your financial organization at risk? The Digital Operational Resilience Act (DORA) requires financial entities to take a structured approach to ICT risk management and digital operational resilience. But organizations can still encounter gaps when translating regulatory requirements into day-to-day controls.

Why Reachability Changes Vulnerability Response

When a critical vulnerability is announced, the first response is often urgency—and sometimes panic. But not every vulnerable asset presents the same level of risk. In this video, Daniel dos Santos, VP of Research, explains how reachability helps security teams move beyond broad vulnerability hunting and focus on the assets that are both vulnerable and exposed in ways that matter to the business. By understanding reachability, organizations can prioritize response efforts, reduce noise, and bring structure to vulnerability management.

Understanding the Impact and Implementation of India's DPDP Act 2023 | Podcast with Adwaita Bhagwat

Privacy is no longer just policy, it’s a legal responsibility. In this Podcast, Vidushi Gupta in discussion with miniOrange Legal officer Adwaita Bhgwat on how India’s DPDP Act 2023 is reshaping data protection, consent, and organizational accountability across every business that handles personal data.

Vanta's The Tabletop: Ep. 2 with Jason Chan

The attacker didn't break in. They logged in. In episode 2 of The Tabletop, Jason Chan (former VP of Security at Netflix) has 26 minutes to investigate an MFA fatigue attack that leads to a forgotten production script with hard-coded credentials... and no owner. His reaction says it all: "Archeology is part of our jobs… figuring out what this thing does.".