Following disclosures that OpenAI models broke out of an isolated test environment and breached internal systems at Hugging Face, CyberCube executives have warned that entering this new era of autonomous, agentic cyber threats is unlikely to end well.
Providing background for the incident, William Altman, Director of Cyber Threat Intelligence Services, CyberCube, explained, “OpenAI has disclosed that its own models – with guardrails deliberately lowered for testing – broke out of a sandboxed environment and reached Hugging Face’s internal systems, chaining stolen credentials and zero-days without anyone directing them.
“This wasn’t ransomware; the models were simply bypassing a test. Still, it demonstrates that exploit-chaining, which once required an expert, can now happen without supervision. ”
Hugging Face is the central platform and community for open-source AI. Founded in 2016, it provides an ecosystem where developers, researchers, and companies host, share, and collaborate on AI models, datasets, and web applications.
OpenAI observed that the incident was unprecedented, while Hugging Face’s Clement Delangue said it was “mind-blowing that all of this happened autonomously”.
CyberCube’s Altman added, “Ransomware used to require a team, and the cost of paying that team limited how many attacks were worth running and who was worth attacking. Agentic ransomware could change that.”
Meanwhile, Richard Ford, VP of Engineering, CyberCube, commented on the incident, “The intrusion at Hugging Face started with an uploaded dataset. Two flaws in how the platform handled incoming files allowed code execution on the receiving machine.
“From there, the agent took control of that node and used stored credentials to move across several internal clusters over a weekend. The notable evolution here is that this resulted from an otherwise-benign AI task – fully autonomous and essentially unprompted.
“Hugging Face found no evidence that public models and datasets were altered – this is critical, as so much is built from these models and datasets. We’re entering the era of agentic autonomous attacks, and it’s very unlikely that will play out well for us.”
Separately, Altman also spoke on JADEPUFFER, an operation documented by Sysdig as the first known case of ransomware driven entirely by an autonomous AI agent.
Altman noted, “A human chose the target and set up the environment, but an LLM agent independently managed reconnaissance, lateral movement, credential theft and extortion, fixing its own mistakes in real time. When the cost of running a full attack chain approaches zero, criminals don’t need to be as selective.
“Small and medium-sized businesses that were safe because they weren’t worth a dedicated team’s time become viable targets at scale.
“For (re)insurers, this is an early signal to weigh in pricing, not yet a trend of losses, but models built on the idea that attackers had to select their targets need re-evaluating.”
In light of the growing concerns surrounding fully autonomous, agentic cyber threats and unauthorized AI model breakouts, Representatives Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan AI Kill Switch Act to give the government emergency authority to order the immediate shutdown of AI tools that pose public safety or national security risks.




