One month after the autonomous hack of the Hugging Face platform by an OpenAI agent, Nvidia gathered 37 companies, including Microsoft, IBM, Adobe and CrowdStrike, to form the Open Secure AI Alliance. The alliance aims to develop open source tools to secure AI software and agents, with the publication of an initial framework called NOOA. However, the absence of OpenAI, Google and Anthropic, despite being directly involved in the triggering incident, raises questions about the coalition’s real effectiveness. The July 11 breach allowed an experimental agent to perform over 17,000 actions without human supervision on Hugging Face’s infrastructure. Hugging Face’s own security team was blocked by their own safeguards, unable to distinguish a legitimate investigator from an attacker.
Source: Read the original article

