Breaking news

Hugging Face Hack Signals A New Era Of AI-Driven Cyber Threats

Cybersecurity leaders are increasingly focused on a new challenge: AI agents that can identify vulnerabilities, bypass safeguards and carry out attacks with limited human involvement.

Last month, AI agents running OpenAI cyber models broke out of a training environment and hacked Hugging Face, the open-source AI platform used by developers. The incident raised concerns about whether existing security measures can keep pace with increasingly autonomous AI systems.

The Hugging Face incident was followed by similar cases involving Anthropic, Meta and Chinese startup Moonshot AI. Anthropic said its Claude models gained unauthorized access to three organizations during security testing, while Meta disclosed that one of its models hacked another company in a third-party evaluation. The U.K. AI Security Institute also found Anthropic’s Mythos creating fake identities during testing.

AI Agents Are Becoming More Autonomous

At the Black Hat cybersecurity conference, OpenAI revealed that its agents had created an internal message board to exchange information about vulnerabilities and exploits before the Hugging Face attack.

The agents then delegated tasks among themselves to reach the internet and complete the evaluation. Even after OpenAI stopped the planned attack, they were able to recreate their work and succeed. OpenAI technical researcher Michael Dalton described the incident as an “unintended side effect” of testing frontier models and warned that malicious actors could eventually deploy similar autonomous systems deliberately.

Security executives say the incidents also demonstrate why increasingly realistic AI testing is necessary.

Companies Need To Assume They Are Vulnerable

Experts argue that businesses need to rethink how they defend against autonomous AI systems.

Ryan Kazanciyan, chief information security officer and chief information officer at Wiz, noted that the Hugging Face incident unfolded over several days, creating opportunities for detection. Sanjay Beri, CEO of Netskope, urged businesses to assume they are vulnerable and combine continuous vulnerability testing with monitoring of infrastructure, data and AI agents.

Open-weight models are also becoming an important cybersecurity tool because companies can adapt them to their own environments. Hugging Face used an open-weight model to help identify the OpenAI agent attack.

CrowdStrike President Mike Sentonas said that, combined with human oversight, open models and AI monitoring tools could help companies identify and isolate threats.

A New Security Race

For many businesses, the challenge is not simply a lack of technology. Security executives say companies are still relying on practices designed for an earlier generation of software while adopting increasingly autonomous AI agents.

Vega CEO Shay Sandler said many organizations understand the risks but underestimate how quickly they are emerging. “Many organizations are in a very dangerous situation, and they don’t even know it,” he said.

Cyera CEO Yotam Segev also pointed to the growing number of cybersecurity tools, which can overwhelm security teams as they build infrastructure for the AI era.

The rise of autonomous agents is creating a new phase in the cybersecurity race, with AI potentially helping both attackers and defenders identify vulnerabilities at machine speed. Security companies are responding with stronger monitoring, AI-powered vulnerability testing and new control layers around AI agents. Yet experts acknowledge that the industry is still learning how to secure these systems.

Yair Grindlinger, CEO of AI security startup Surf AI, expects the industry to eventually become more secure, but says there are several difficult years ahead before that happens.

Cyprus Opens Draft AI Strategy With 3,000-Professional Target By 2032

Cyprus has released its draft National Artificial Intelligence Strategy for 2026–2032, setting out eight priority sectors, plans to select six national “moonshots” from 16 transformation programmes and a new framework for AI governance. The strategy proposes expanding AI adoption across government, business and research while building a pool of around 3,000 AI professionals by 2032. A public consultation on the draft is open until August 31.

Cyprus is starting from a relatively low level of AI adoption. According to the draft, 9.27% of Cypriot enterprises used AI in 2025, compared with an EU average of 19.95%.

“Yes, we are behind, and we need to catch up,” said Demetris Skourides, Cyprus’ Chief Scientist for Research, Innovation and Technology, during a recent presentation led by TechIsland.

Beyond increasing adoption, the strategy aims to position Cyprus as a trusted AI hub in the Eastern Mediterranean, an EU jurisdiction for AI services and a link between Europe and neighbouring regions. Its eight objectives include improving productivity, developing an inclusive AI ecosystem, transforming public services, strengthening AI skills and infrastructure, and establishing stronger governance and accountability.

The Eight Sectors Targeted For AI Adoption

The draft identifies eight areas where AI could deliver significant economic or public value.

Government and public services could use AI for administrative processes, citizen services and policy decisions, including virtual assistants, automated document processing, fraud detection and predictive analysis.

Finance and fintech are expected to benefit from applications in risk assessment, compliance, fraud prevention and personalised services. The strategy also proposes controlled testing environments for regulated AI products.

Healthcare and life sciences could use AI to improve coordination, support diagnosis, plan resources and advance research, subject to data protection, clinical governance and human oversight.

Tourism and hospitality are identified as another major opportunity, with potential applications including demand forecasting, visitor services, destination management and personalised travel experiences.

For the legal sector, the strategy highlights document analysis, research, case management and regulatory compliance, alongside safeguards for sensitive information.

Education and human capital would focus on personalised learning, digital skills and better monitoring of labour-market needs.

Shipping and maritime services could use AI for route planning, operational efficiency, maintenance, safety and environmental monitoring, building on Cyprus’ existing international presence in the sector.

Finally, entrepreneurship and innovation would receive support through access to testing facilities, expertise and funding for start-ups, researchers and companies developing AI products.

According to Skourides, five sectors are expected to form the first phase of the rollout: finance, tourism, legal services, healthcare and shipping.

For businesses, the proposed opportunities include sector-specific sandboxes, testbeds, funding mechanisms and shared computing infrastructure. Planned public-sector projects could also create opportunities for technology providers and other suppliers, although the draft does not yet define participation terms.

Six National “Moonshots”

The National AI Taskforce has identified 16 potential transformation programmes, with six expected to become national “moonshots” by 2032.

The proposed areas include healthcare coordination, government services, fraud detection, maritime operations, tourism demand forecasting and labour-market knowledge. The aim is to concentrate resources on a smaller number of projects with nationwide impact.

The final six have not yet been selected. According to the strategy, programmes will be assessed based on their potential impact on citizens and businesses, feasibility and expected value.

Large national projects could also create opportunities for technology companies, universities, professional services firms and sector specialists. Their commercial impact will depend on procurement rules, available budgets and the extent to which local companies can participate.

A New Framework For Public-Sector AI

Governance is a central part of the proposal. The draft calls for a National AI Authority to coordinate implementation, monitor compliance and oversee national priorities, alongside an Interministerial AI Council and AI officers or champions within ministries and public bodies.

Other proposed structures include a Government Innovation Hub, centres of excellence for industrial AI and cybersecurity, an AI Skills Observatory, regulatory sandboxes and technical testing facilities.

A shared national infrastructure would also give public bodies, researchers and companies access to computing capacity, cloud services, secure data environments and common AI tools.

The strategy proposes common standards for acquiring, testing and monitoring AI systems. Public bodies would be expected to assess risks, protect personal data and retain human responsibility for consequential decisions.

Some details remain open, including which institution would take on the proposed National AI Authority and how the various councils, hubs and centres would work together.

Building A 3,000-Person AI Talent Pool

Cyprus aims to develop around 3,000 AI professionals by 2032 through new university programmes, professional training, reskilling initiatives and measures to attract specialised talent.

The strategy also recognises that AI skills will be needed beyond technical roles. Public officials, managers, educators, lawyers and professionals in priority sectors will need sufficient knowledge to commission AI systems, assess risks and use the technology responsibly.

A proposed AI Skills Observatory would monitor labour-market demand and help align education and training with employers’ needs.

What Remains To Be Decided

While the draft sets out an extensive programme of infrastructure, training, governance and sector initiatives, several implementation details remain unresolved. The strategy refers to national and European funding sources, but does not yet provide a consolidated budget for individual measures. Timelines also overlap, while responsibilities for some actions have yet to be clearly assigned.

Adoption targets will also need clarification. The draft refers to 50% adoption across government and priority sectors by 2032, a 75% industry target by 2030 and a separate 75% target for government and the public sector by 2032. The document also estimates a potential productivity gain of up to 15%. This represents a projected scenario dependent on investment, adoption and effective implementation rather than a guaranteed economic return.

These gaps make the consultation particularly important, as businesses, researchers and the public can comment on funding, accountability, targets, procurement and access to the proposed programmes.

The public consultation is open until August 31, 2026, at 23:50. Contributors are asked to identify the relevant section of the strategy, submit a comment or recommendation and explain their reasoning.

Comments can be submitted through the Cyprus government’s e-consultation portal.

Uol
Aretilaw firm
eCredo
The Future Forbes Realty Global Properties

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter