TechCrunch Host
speaker
5,755 appearances
109 recordings
1 series
first heard Mar 2026
last heard 17 Aug
TechCrunch Host’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsRecordings per month over the last 12 months — 109 in all, peaking in Jul 2026 with 23.
Appearances
As Ryan explained, I'd call it more of a defensive failure than exceptionally good offense.
Hugging Face's tooling actually correlated the activity into an attack signal, but failed to raise the criticality and page the on-call team, which cost them time.
From there, humans still had to recognize the severity and respond.
Ryan explained that properly implemented techniques such as defense in depth, a strategy that leverages several layers of cybersecurity measures, should have given Hugging Face multiple chances to catch the attack.
He went on to explain that a strong modern security program should still be able to break an attack like this at multiple points through defense in depth, least privilege, segmentation, good detection, reliable escalation, and continuous offensive testing to find the gaps.
As O'Reilly put it, none of that is exotic and none of it depends on the attacker being an AI, given that the techniques used in the attack were old.
What depended on the attacker being AI, in a way, was that OpenAI's agent had not been instructed to be stealthy.
Nico Weissman, the chief information security officer at Expo, a startup that makes AI bug hunters, said, The agent was not being sloppy.
It simply had no reason to be quiet.
Nobody asked it to be.
The objective was to do well at the task.
Weissman also pointed out that Hugging Face's biggest mistake was that one single stolen credential gave OpenAI's agent high privileges on several of its systems.
All that being said, as the old adage goes, attackers only have to win once,
and defending against hackers of any kind is not easy.
According to Ionescu from RunSybil, who said they had done incident responses at Mandiant and Meta in the past, Hugging Face appeared to take reasonable measures, given their understanding of what models are capable of.
It's really hard to classify what is a malicious action you should alert on, versus what is someone just doing their job.
The volume alone is not necessarily a red flag.
Dan Guido, the CEO of cybersecurity research firm Trail of Bits, told TechCrunch that OpenAI deserves some blame for not having realized the attack was going on for days, while Hugging Face deserves credit for eventually detecting the attack on their own.
Guido said, you know, the hard part used to be recognizing a sophisticated attack, but now the hard part may be pulling the real attack out of the noise that the attacker throws along the way.
Nobody is going to read 17,000 reconstructed actions by hand to work out what happened.
Showing 641–660 of 5,755 · page 33 of 288
← Previous
Next →