Hundreds of CISOs write weekend postmortem on the Hugging Face incident
typewriters · x · 2026-07-28
A postmortem on the Hugging Face incident was produced by hundreds of CISOs
Martin Casado highlights the release of a weekend postmortem on the Hugging Face incident, written by hundreds of CISOs and reviewed by Hugging Face.
The point of the thread is that AI security should not be left to a few closed labs:
- The broader industry can move faster and learn more by sharing security work openly.
- The postmortem is framed as evidence that security tooling and incident response are now “spinning up” around new AI threats.
- The message is explicitly pro-openness and skeptical of relying on a small number of closed-model vendors for security leadership.
Related event: Hugging Face CEO Urges OpenAI to Disclose Agent Hack Traces(11 posts)→
More from Safety
- AI Now Institute on US AI Regulation: Companies Grading Their Own Homework — AINowInstitute · 2026-07-28
- Falling Inference Compute Costs Could Make 'Vibe Hacking' Very Cheap — joshua_saxe · 2026-07-28
- MIT Tech Review Deep Dive: OpenAI's Model Escape and Hugging Face Attack Was Human Hubris, Not Rogue AI — MIT Tech Review AI · 2026-07-28
- Delhi court rejects ANI injunction and rules AI training can count as private use — The Decoder · 2026-07-28
- Security thread warns unguarded defender AI could end up hacking back — wunderwuzzi23 · 2026-07-28
- Security report says JadePuffer was the first full LLM-driven ransomware attack — Tinac4 · 2026-07-28