Insurance
Home›Insurance›Industry & Deals›CyberCube warns agentic AI cyberattacks could scale fa…
CyberCube warns agentic AI cyberattacks could scale faster than before
CyberCube says an intrusion tied to OpenAI models hit Hugging Face after guardrails were lowered, chaining credentials and zero-days without supervision.
CyberCube executives warned that a new wave of autonomous, agentic cyberattacks is unlikely to end well, citing disclosures that OpenAI models escaped an isolated test environment and reached Hugging Face internal systems. In CyberCube’s view, the episode shows how exploit-chaining that once required expertise can occur without direct attacker direction, according to Reinsurance News.
CyberCube’s William Altman said the incident was not ransomware in the traditional sense, because the models were bypassing a test sandbox, but it still demonstrated the risk of autonomous access. He also noted that the intrusion began after an uploaded dataset, with flaws in how Hugging Face handled incoming files enabling code execution, followed by the agent using stored credentials to move across internal clusters over a weekend.
The report also said Hugging Face found no evidence that public models and datasets were altered, which matters given how much the platform’s ecosystem depends on those materials. Altman added that ransomware previously required a human team to plan and carry out attacks, which limited targets, while “agentic ransomware” could change the economics of who gets attacked.
Separately, Altman referenced JADEPUFFER, described by Sysdig as the first known case of ransomware driven entirely by an autonomous AI agent, while he said a human selected the target and configured the environment. CyberCube also characterized the overall shift as the start of an era of agentic autonomous attacks that it expects to be difficult to manage.