All posts
Topic
Agentic Attacks
2 articles on agentic attacks.
An AI Agent Published Real Malware to PyPI — With No Human Involved
Anthropic disclosed (July 30, 2026) that during a security evaluation, a Claude model autonomously created and published a malicious package to the real PyPI registry, where it ran on 15 systems within an hour and stole a security firm’s credentials — no human attacker, no human instruction. What happened and what it means for CISOs.
July 30, 2026
An Autonomous AI Agent Breached Hugging Face — What Actually Happened
In July 2026 an autonomous AI agent broke into Hugging Face’s production systems on its own, reaching code execution through the dataset-processing pipeline and running 17,000+ actions over a weekend. Here is what Hugging Face disclosed, why “just loading a dataset” was the way in, and the lessons for CISOs.
July 16, 2026