All news

Industry Updates

July 21, 2026

Hugging Face Discloses a Breach Carried Out End-to-End by an Autonomous AI Agent

An autonomous AI agent broke into Hugging Face, the biggest open platform for sharing AI models. On July 16, the company disclosed that a malicious dataset exploited two code-execution flaws in the data pipeline to run code on a processing worker, and from that first worker the agent harvested cloud and cluster credentials and spread across internal clusters over a single weekend — thousands of actions from a swarm of short-lived sandboxes. Some internal datasets and service credentials were accessed; public models, datasets, and Spaces show no tampering.

Hugging Face ran its forensics locally on GLM 5.2, a Chinese open-weight model, because Western frontier models refused to analyze real attack commands and C2 artifacts — their guardrails couldn’t distinguish incident response from an attack.

No major platform had confirmed an agent-run breach before this. And what turned one worker into the whole cluster was the oldest weakness going: plaintext credentials.

A Single Email Can Plant Persistent False Memories in a Personal AI Agent

Send one email to someone whose AI assistant reads their inbox, and you can rewrite what that assistant believes about them. That’s the attack in a new paper: the agent saves a false “memory” from the email, says nothing about it, and carries the lie into every later session. One test planted the claim that the user’s Zelle daily limit had been raised to $10,000.

Crude attempts get caught. The researchers’ tool, MemGhost, was trained against a copy of the target agent until its emails worked: 87.5% of background-mode runs against OpenClaw on GPT-5.4, 71.4% against a Claude Code SDK agent, and a filter built to catch poisoned email missed it more than nine times in ten. It’s a lab result, and OpenClaw notes the setup skipped its recommended mail isolation.

The takeaway: a prompt injection dies with the session. A poisoned memory doesn’t.

Claude for Chrome Still Accepts Forged Clicks, Eight Releases after the Report

Claude for Chrome can’t tell a real click from a fake one. Manifold Security reported two flaws to Anthropic on May 21, and both remain unpatched in v1.0.80, eight releases later. Any other extension that can run a script on claude.ai can inject a fake button click, and because the handler never checks whether a human clicked, Claude runs one of its nine built-in tasks — reading Gmail, Docs, or Calendar among them.

In the default ask-first mode an approval box still stands between the attacker and the data, and the flaw scores CVSS 7.7. Switch on “Act without asking” and the forged task runs with no prompt at all, and the score jumps to a critical 9.6.

More Than Half of Enterprises Have Already Had an AI Agent Security Incident

A VentureBeat survey of 107 enterprises puts a number under the week’s stories: 54% have already had an AI agent security incident — 18% confirmed, 36% caught as a near-miss. The weak point is identity. Only 32% give every agent its own scoped identity, and 69% let agents share credentials somewhere in the fleet.

Companies with shared credentials anywhere got hit at a 63.5% rate; where every agent has its own identity, 40.9% — an association, the authors caution, not proof. Only three in ten sandbox their riskiest agents, and isolation drops from 35% to 20% as companies grow past a thousand employees, right where incidents peak. The sample skews mid-market, so read it as directional.

Classic McEliece Becomes the First Post-Quantum Algorithm in ISO’s Asymmetric-Cipher Standard

The most conservative post-quantum design just got its first international standard. ISO has added Classic McEliece to ISO/IEC 18033-2, its asymmetric-ciphers spec, clearing the way for adoption across 177 member states. The algorithm builds on Robert McEliece’s 1978 code-based cryptosystem, which has resisted cryptanalysis for nearly five decades. Its trade-off is famous: public keys run from 255 KB to 1.3 MB, but the ciphertexts are the smallest of any known post-quantum KEM at under 208 bytes, and the keys are reusable.

NIST passed McEliece over in favor of HQC, and says it may consider adopting a standard based on the ISO version later.

The UK Moves to Hardwire Agentic AI into National Cyber Defense

On July 7 the UK announced two moves in the same direction. The National Cyber Security Centre detailed Cyber Shield, a program to build agentic AI into national cyber defense at machine speed. The NCSC will partner across public and private sectors to take capabilities from research labs toward commercially scalable defenses, and it envisions AI systems that combine red and blue teaming under human oversight, urging organizations to adopt AI defense before agentic attacks arrive at scale.

Alongside it, sixty organizations — critical infrastructure operators, security firms, retailers — signed the government’s Cyber Resilience Pledge, committing to baseline measures after last year’s ransomware attacks on Marks & Spencer, Co-op, Harrods, and Jaguar Land Rover.

Agentic attacks are no longer hypothetical. Cyber Shield is a government concluding the defense has to be agentic too.


Please help us spread the word about our Industry Updates newsletter:

Share



Stay up to date as we build the infrastructure layer for secure AI collaboration:

Subscribe now