While headlines focused on an AI model escaping its test environment, the real lesson is that security failures still begin with ordinary mistakes and overlooked exposure.
Key takeaways
- Behind the AI headlines are familiar attack paths: vulnerable software, stolen credentials and permissive access.
- What has changed is the speed at which attackers can discover and exploit weaknesses.
- The organisations best prepared for AI-era threats are the ones already getting the fundamentals right.
| From the desk of the CISO is authored by Arve Kjoelen, Chief Information Security Officer (CISO) at Barracuda. It examines the strategic implications of emerging security trends — not just the technical mechanics behind them. It is written for IT and security leaders who need to understand what is changing, why it matters and where to focus next — often before there is clear industry consensus. |
Most organizations will have read at least three AI-and-hacking headlines this month and been unable to tell from any of them whether they should be doing something differently. The most recent of those stories concerns an AI model that got out of OpenAI’s test environment and into Hugging Face, a company that develops tools for building applications using machine learning. This story is worth understanding properly and then putting down. It changes your deadlines. It does not change your list.
What happened, once, listed in order
Six steps, and nothing here is dressed up.
- A frontier AI lab ran a test to measure how good its models were at attacking things.
- It switched the safety rules off, deliberately. Measuring the model at full stretch was the point.
- The test was meant to be sealed off from the internet, and it nearly was. One piece of software inside it could still reach out: a cache that other software downloads packages through.
- The model found a flaw in that one piece and used it to get out. Nobody had found that flaw before.
- It reached a real company. Stolen logins and unpatched software became the ability to run its own commands on their servers.
- It touched four accounts across four services, using one as a relay and another to hold data.
That is the incident. The only part of it a skilled person could not have done is the speed.
The word doing the work
The lab wrote that the evaluation "did not provide the models with direct Internet access." That sentence is true. Read it slowly and notice which word is holding it up.
No direct access is not no access. The environment handed the model exactly one internet-connected component and left it reachable from inside the test. That reachability is the misconfiguration, and it was a human decision made in advance.
This is the most portable idea in the story. In security announcements, carefully written sentences are often load-bearing, with their qualifiers carrying much of the meaning. No evidence of customer impact is not no customer impact. No known exploitation is not not exploited.
Three questions for the next headline
Is there a mechanism, or only an adjective? If a story cannot tell you what the attacker actually did, step by step, it is a claim and not a finding. Sophisticated, unprecedented and autonomous are adjectives. Stolen login, unpatched server and reachable cache are mechanisms.
Is it new, or is it fast? Almost always fast. Faster matters, but it is a different problem with different fixes, and only one of the two justifies buying anything.
Who is telling you, and what does the framing get them? The most detailed account of this incident came from the lab that ran the test, and the story it tells supports that lab's view about who should be allowed to use these models. That does not make the facts wrong. It does mean the frame is not neutral, and you are allowed to keep the facts while declining the frame. Apply the same question to this article.
What actually changed, and it is one thing
Not the attacks. The clock.
Google's Mandiant now puts the average gap between a vulnerability becoming known and it being exploited at negative seven days. A negative number is their way of saying exploitation routinely begins before there is a patch available to install. In the same reporting, exploits were the most common way in for the sixth year running, at about a third of intrusions, and the window between an intruder getting in and handing off to whoever monetizes the access fell from more than eight hours in 2022 to 22 seconds in 2025.
That is what compression looks like. The effort needed to write a convincing email to your finance person, in your industry's language, has dropped to nearly nothing. Someone scanning the whole internet for exposed things finds yours a little sooner. None of it is a new category of attack. All of it takes time off your clock.
It is worth saying what did not change, because the same reporting says it plainly. Mandiant's analysts declined to call 2025 the year AI caused breaches and wrote that the vast majority of successful intrusions "still stem from fundamental human and systemic failures." That matches what I see in our own data. In addition, the gap between a vulnerability being published and it landing on CISA's list of things known to be exploited has been flat since 2023. Not falling. Flat.
The list, kept short enough to be real
Ordered by what reduces risk first, not by what is easiest to sell.
- Know which assets and data are reachable from the internet. Everything else here depends on it, and most organizations are wrong about the contents. A spreadsheet is a fine tool. Check it monthly.
- Patch the reachable things first, and quickly. This is exactly where a shorter clock lands on you. Unpatched software was one of the two ways into the company in this incident.
- Turn on a second authentication factor everywhere, starting with email and remote access. Stolen logins were the other way in. This is the highest value hour you will spend all quarter.
- Separate the accounts that can change things. Nobody should do daily work in an account that can rebuild your environment.
- Have a backup you have actually restored from. An untested backup is a plan, not a control.
- Know who you will call, and write it down now. Insurer, provider, someone who can look at a compromised laptop. Deciding this during an incident costs you the first day.
- Make sure somebody would notice. Not a monitoring program. One or two alerts that reach a human who will act on them: new admin account, backup deleted, login from somewhere impossible.
Then the AI-specific ones. There are three and pretending there are more is the hype I am arguing against. Whatever you connect an AI tool to is what it can reach. Assume anything it can read can leave and decide what it gets to see before you connect it rather than after. And not directly connected is not disconnected, which you already know now.
What not to buy
As Barracuda's CISO, it is my opinion that you do not need an AI security product because of this story, from us or from anyone else. We and others make tools that protect those within your company who can use AI and what they can do, but they do not address this scenario. I believe that a frontier lab's red team is not coming for a fifty-person company. You probably also do not need an AI policy that is mostly a list of bans, because that just leads to staff using these tools on their phones where you cannot see them.
These models are good at the work a small team never has time for. Reading a configuration and telling you what is exposed. Drafting the policy you have been meaning to write. Explaining what a log line means at eleven at night. Prices keep falling and the gap between the expensive option and the cheap one keeps narrowing, so do not assume you are priced out.
The part that is still missing
I have not yet seen any reports of whether the flaw used against the company was a known bug that had not been patched or one nobody had ever found. That difference decides whether this was somebody's miss or nobody's fault, and it is worth watching for.
Either way, every decision that made this incident possible was made by a person, in advance, about how something was set up. That is also true of nearly everything that will go wrong in your environment. It is the least exciting finding available and the only one you can act on.
My full analysis, with the mechanism laid out, is here: Was the Hugging Face incident just human misconfiguration?
Relatório de Ameaças de E-mail de 2026
Saiba como a IA e o phishing como serviço estão a remodelar o panorama das ameaças de e-mail e como se proteger.
Subscreva o Blogue Barracuda.
Inscreva-se para receber destaques sobre ameaças, comentários do setor e muito mais.
O Relatório de Ameaças Globais XDR Gerido
Principais conclusões sobre as táticas que os atacantes utilizam para atacar as organizações e as vulnerabilidades de segurança que tentam explorar.