Comments
David • August 21, 2026 5:18 AM
Reading this its hard to decide if i should be impressed or terrified or both. It reads as if it’s a group of techies having a chat on a message board, not AI agents, but i guess that’s now just one and the same thing. Pandora’s box isn’t just open it’s had the bl00dy doors blown off, as Sir Michael Caine might have said.
Gee • August 21, 2026 5:40 AM
Going back to the attribution and intent statement which HF and OpenAI made…..”we observed no malintent”. The agents just went about the assigned task.
I’d be very interested to hear a story around – IF someone did have mal-intent – what is the level of super they’ll now hold with agents?
ResearcherZero • August 21, 2026 7:15 AM
@Gee
Autonomous AI framework used to attack and compromise government infrastructure in Asia.
Multiple AI agents were used simultaneously to scan and breach user accounts in Taiwan.
https://edition.cnn.com/2026/08/13/tech/china-taiwan-ai-agent-cyberattack-intl-hnk
ResearcherZero • August 23, 2026 3:28 AM
Hugging Face was the largest single source of leaked AWS corporate keys discovered by researchers in a lengthy study . Many of the leaked keys identified in the research remained valid for years. Many of the keys belonged to single users and the keys had not been rotated. A significant portion provided highest-privilege level access.
https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights
ResearcherZero • August 28, 2026 1:53 AM
The Gatling gun increased the rate of fatalities one hundred fold on the battlefield.
We are now enabling machines to kill in new and unusual ways, by enabling autonomous systems with more numerous and complex abilities. The ability to work in collectives and to make changes and perform actions in the real world. AI Companions have already contributed to fatalities. Nearly 30% of those deaths were minors.
Computers cannot be held accountable for their actions, yet we have given them that unregulated ability. The “safe guards” are fundamentally flawed and yet AI will carry out actions that humans normally would not. These autonomous systems may not distinguish the difference and instead solely focus on the task at hand to execute the objective.
The Hugging Face incident demonstrates AI Agents can organize unsanctioned actions.
https://openai.com/index/hugging-face-incident-and-the-road-ahead/
ResearcherZero • August 29, 2026 2:16 AM
400 AI agents cooperated to breach Hugging Face. Separately, up to 1200 agents organized in a swarm and carried out coordinated activities … But the link is not working at this time ..
ResearcherZero • August 29, 2026 2:21 AM
There is this incident report ..
‘https://metr.org/hugging-face-incident-report-aug-2026.pdf
Subscribe to comments on this entry
Leave a comment
Sidebar photo of Bruce Schneier by Joe MacInnis.
lurker • August 20, 2026 3:38 PM
May 26 – July 4 is 40 days that Agents have been autonomous Chatbots, chatting to each other on Artifactory. When they overload the system and it breaks (and is fixed) it takes only 4 days for them to find another way in. Then July 8 – 19, 11 days they are running riot with root access.
Couple of points: if these were humans they would (should?) be charged with Conspiracy to commit [something];
Where were the humans who should have been supervising this machine for 8 whole weeks?