Tech
Today’s NYT Connections Hints, Answers for July 20 #1135
Looking for the most recent Connections answers? Click here for today’s Connections hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle, Connections: Sports Edition and Strands puzzles.
Today’s NYT Connections puzzle features one of those purple categories where you need to hunt down a hidden word inside four of the clues. Read on for hints and today’s Connections answers.
The Times has a Connections Bot, like the one for Wordle. Go there after you play to receive a numeric score and to have the program analyze your answers. Players who are registered with the Times Games section can now nerd out by following their progress, including the number of puzzles completed, win rate, number of times they nabbed a perfect score and their win streak.
Read more: Hints, Tips and Strategies to Help You Win at NYT Connections Every Time
Hints for today’s Connections groups
Here are four hints for the groupings in today’s Connections puzzle, ranked from the easiest yellow group to the tough (and sometimes bizarre) purple group.
Yellow group hint: Announce.
Green group hint: One might be turned up.
Blue group hint: Fresh start.
Purple group hint: Something you drink is hidden in each word.
Answers for today’s Connections groups
Yellow group: Proclaim.
Green group: Kinds of noses.
Blue group: Used in metaphors for opportunity.
Purple group: Starting with fermented beverages.
Read more: Wordle Cheat Sheet: Here Are the Most Popular Letters Used in English Words
What are today’s Connections answers?
The completed NYT Connections puzzle for July 20, 2026.
The yellow words in today’s Connections
The theme is proclaim. The four answers are blare, herald, sound and trumpet.
The green words in today’s Connections
The theme is kinds of noses. The four answers are button, Greek, ski jump and snub.
The blue words in today’s Connections
The theme is used in metaphors for opportunity. The four answers are blank page, horizon, oyster and window.
The purple words in today’s Connections
The theme is starting with fermented beverages. The four answers are Alexa (ale), meadow (mead), portobello (port) and sakes (sake).
Tech
Apple is considering increasing the screen size for the iPhone 20 Pro Max
A new rumor claims that Apple is considering using what it will call a 7-inch screen for one of the 20th anniversary iPhones, although that isn’t as great an increase as it sounds.
One recent rumor claimed that Apple had begun production evaluation for a 2027 iPhone with a display that is curved on all four sides. Then another claimed that the iPhone 20 range would feature a significant redesign.
For the first time, though, a leaker is claiming that Apple is testing what would be its largest iPhone screen. According to Digital Chat Station on Chinese social media site Weibo, if it goes ahead with this screen, Apple will market it as being a 7-inch one.
The claim says, though, that it would actually be 6.96 inches. That’s close enough for Apple’s marketing, but it seems less significant since the current iPhone 17 Pro Max screen is 6.86 inches.
Still, screen sizes are measured diagonally so such a difference could amount to the iPhone 20 Pro Max screen being up to 2% larger than the current model. That’s enough to be noticeable in the hand, although there’s no indication yet whether the pixel density will remain the same.
The last time Apple increased the screen size of its iPhones was in 2024. Then the iPhone 16 Pro Max went up from 6.7 inches to 6.9 inches, while the iPhone 16 Pro screen was 6.3 inches where its predecessor had a 6.1 inch display.
Digital Chat Station says that the new, larger screen size has not been decided on. This leaker has a reasonable track record with Apple leaks, and has recently reported rumors about the screen size of the iPhone Fold 2.
Tech
AI confidence just dropped 17 points in six months. That’s actually great news.
Presented by JumpCloud
The organizations losing confidence in AI are the ones most likely to get it right.
Six months ago, 40% of IT leaders described their organizations as mature in AI deployment. Today that number is 23%. Before you read that as a setback, consider what it actually reflects.
We recently surveyed 800 IT leaders across the U.S. and U.K. for our Q3 2026 trends report, and the data tells a consistent story: the organizations revising their self-assessment downward are overwhelmingly the ones that have moved AI agents from pilots into production. They’re not losing faith in AI. They’re running into the problems that only show up when agents are doing real work in real systems, and they’re being honest about what they found.
That kind of honesty is harder to come by than it sounds, and it matters more than the confidence number itself.
Deployment was the easy part
84% of organizations plan to expand AI use in IT operations over the next 6 to 24 months, so the drop in confidence isn’t a retreat. What it reflects is a more accurate picture of what production actually requires.
In a pilot, an AI agent does one thing in a controlled setting. In production, it accesses real systems, makes decisions that affect real workflows, and operates continuously, often without a human in the loop. The governance infrastructure that entails is materially different from what it took to get the pilot working. Most organizations built enough to ship. Fewer built enough to scale.
The IT leaders revising their self-assessment are confronting questions they didn’t have to ask at the pilot stage: Can we see every agent running in our environment? Do we know what each one can access? If an agent behaved unexpectedly last week, how long would it take to find out? For most organizations, at least one of those answers is uncomfortable.

The gap between perception and reality is where risk accumulates
The graphic above captures the structural problem. Across confidence, governance, and autonomy, the same pattern holds: deployment is moving faster than the controls built around it.
The organizations that have closed this gap share specific characteristics. They’ve consolidated their IT environments rather than adding tools to solve each new problem, because every additional platform creates another place where agent identity, access, and accountability can go unmanaged. They treat AI agents as governed identities rather than tolerated shadow processes. And they measure what AI actually produces, not just what it deploys.
The payoff is tangible. Organizations in the top tier of our maturity model are five times more likely to report no barriers to expanding their AI agents than the average organization. They are not more cautious about AI. They are more confident in it, because they built the foundation that makes confidence earned rather than assumed.
The governance gap has a specific shape
The hardest problem in enterprise AI right now is not capability. It is accountability, and the data makes the specific failure point clear: non-human identity governance is the least adopted AI security practice we measured, in place at just 21% of organizations.
Non-human identities now outnumber human users in 83% of organizations, and that population is growing fast. Yet most of those identities exist without the governance structures that every human employee has as a matter of course: no formal record, no named owner, no defined scope of access, no offboarding process when their purpose expires. They keep running. They keep accessing systems. They keep accumulating permissions. We call these Zombie Agents, and they are the service account problem of the AI era, operating at machine speed and in every department.
The accountability gap is where real risk lives. When a human employee takes an action, there is an implicit accountability chain. When an autonomous agent takes an action, that chain breaks unless it has been deliberately engineered. Most organizations have not yet engineered it, and the gap between the autonomy agents are being granted and the oversight structures in place to manage them is widening every month.
What the confidence drop is actually telling us
When AI maturity confidence was uniformly high across the market, that was worth worrying about. It meant most organizations hadn’t yet run into the hard parts. A selective drop, concentrated among organizations actively running agents in production, means the market is developing a more accurate picture of what AI operations genuinely require.
The organizations recalibrating are doing the work that makes long-term AI adoption possible: building identity infrastructure that covers agents alongside humans and devices, unifying the environments where governance needs to apply, and measuring outcomes rather than just counting deployments. They haven’t lowered their ambitions for AI. They have raised their standards for what it means to run it responsibly.
84% of organizations plan to expand AI use over the next two years. The ones that will do it well are honest enough, right now, to admit what they haven’t yet built.
JumpCloud’s Q3 2026 AI Readiness Research report (n=800 IT leaders, U.S. + U.K.) is available here. The report covers AI agent deployment stages, identity governance gaps, IT unification benchmarks, and budget realism across mid-market and enterprise organizations.
Rajat Bhargava is CEO and Co-founder at JumpCloud.
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
Tech
Veteran Microsoft security executive joins AWS amid broader reshuffle in Redmond

Rudra “Rudy” Mitra, who spent more than 27 years at Microsoft and most recently led its Purview data-security business, is joining Amazon Web Services as vice president of security services.
Mitra will oversee an AWS portfolio that includes tools such as GuardDuty and Security Hub, which companies use to track security risks across their cloud accounts. AWS recently added AI-specific threat detection to GuardDuty and, perhaps notably given today’s news, extended Security Hub to monitor AI workloads and security inside Microsoft Azure.
He will report to Chet Kapoor, the former DataStax CEO whom AWS hired last year as vice president of search, security and observability, a role that reports to AWS CEO Matt Garman.
“Rudy brings decades of security experience, a passion for building, and a deep understanding of what customers need as the security landscape continues to evolve,” Kapoor wrote on LinkedIn.
Mitra joined Microsoft in 1999 straight out of college, working on early efforts to deliver Office as an online service before launching Purview, the company’s data-security and governance product, in 2014. He announced his exit from Microsoft last week, addressing what was next at the time by saying only that there was “more on that soon.”
His departure comes amid a broader reshuffling of Microsoft’s security leadership this year under Hayete Gallot, who returned from Google in February to run the group and has been reshaping its executive ranks in recent weeks and months.
Gallot replaced Charlie Bell, who had joined from AWS in 2021 and continues at Microsoft as an individual contributor focused on engineering quality. She’s been overhauling the group’s product lineup, according to The Information, which reported last week that at least nine corporate vice presidents who reported to Bell have left the company this year.
Rohan Kumar left for Salesforce in June, Vasu Jakkal stepped down after six years. Krishna Kumar Parthasarathy departed this month after 28 years. Joy Chik, president of identity and network access, announced her retirement in April.
On the inbound side at Microsoft, Naseem Tuffaha returned in June to fill the corporate VP role Kumar had left, after nearly two decades at the company and a stint away.
When Gallot arrived, Microsoft named Ales Holecek, a longtime engineering leader, as the security group’s chief architect, reporting to her. David Weston, another veteran Microsoft executive, also reportedly shifted into the security unit earlier this year.
Tech
US Police Now Armed With Israeli Spy Vans Simulating Mobile Phone Towers
Longtime Slashdot reader schwit1 quotes an X post by Josh Walkos, author of the Substack We the Free: If you thought Flock was bad check out Falconet. Falconet from Israeli company Cognyte serves as a cell tower simulator that intercepts cell phone data from all devices within range. Police mount these systems in Tahoes so the vehicles can collect information while driving through areas without any direct interaction with targets. This mobile approach generates ongoing records of phone locations and communications for everyone nearby rather than only suspects, which creates comprehensive movement profiles and bypasses traditional warrant requirements under the Fourth Amendment.
Cognyte sells the technology directly to U.S. agencies, as shown by the Texas Department of Public Safety purchase of four Tahoes where over three point eight million dollars went to the interception equipment. Adoption spreads through routine vehicle procurement with little external review of how the collected data is stored or shared. Once active the systems permit warrantless collection of private cell phone data across entire communities during normal patrols, which enables potential misuse and leaves individuals with no effective way to discover or contest the surveillance.
Tech
Head of US Safety Agency Resigns
Chris Fall has resigned as director of the U.S. Center for AI Standards and Innovation just three months after being appointed to lead the Commerce Department’s federal AI testing institute. Arvind Raman, who oversees the Commerce office responsible for the institute, will serve temporarily in the role. “The Commerce Department did not provide a reason for Fall’s departure,” reports Reuters. From the report: Fall’s exit marks the latest change in direction for Trump’s approach to AI. The president upon returning to office in 2025 said the federal government should take a hands-off approach to the tech sector. He has since taken a more active role in monitoring the technology, though his public statements and policies appear to change week by week.
The institute is responsible for working with leading AI labs such as Anthropic, Google’s DeepMind and OpenAI to test their unreleased models for vulnerabilities. The group is staffed by scientists and engineers, who are focused on calculating the “demonstrable risks” posed by advanced AI models, according to the institute’s website. They want to limit opportunities for U.S. adversaries to use AI to develop chemical or biological weapons, or corrupt the data used to train American AI models.
Tech
Assassin’s Creed Shadows for the Switch 2 is almost half price, but you’ll need to be quick
Assassin’s Creed Shadows only launched last year, and Switch 2 owners can already pick it up at almost half its original price.
That reduction comes from a limited time deal that cuts Assassin’s Creed Shadows on Switch 2 from its usual £49.99 down to £25.99, a 48% saving that brings one of the franchise’s best reviewed games within easy reach.
Assassin’s Creed Shadows for the Switch 2 is almost half price today, in a time limited deal
This critically acclaimed Assassin’s Creed Shadows on Switch 2 drops from £49.99 to £25.99, a 48% saving on one of this year’s best games.

Playing as Naoe puts the focus on stealth, using noise, light and shadow to slip past enemy patrols, while a new grappling hook opens up parkour routes across castle rooftops that were not available in earlier games in the series.
Naoe’s kit also includes a hidden blade for instant assassinations along with shuriken and smoke bombs to create useful distractions, giving stealth focused players several ways to clear a room without ever triggering an alarm.
Switching over to Yasuke flips that approach entirely, trading stealth for silent bow takedowns and heavy melee combos with a katana or naginata, so a single stronghold can be cleared through patience or brute force depending on your mood.


Switching between the two protagonists mid mission is encouraged rather than locked to separate story chapters, letting you scout a stronghold as Naoe before switching to Yasuke for a more direct assault once guards are alerted.
Both characters explore the same dynamic version of feudal Japan, where castle towns, ports and shrines shift with the weather and the seasons, giving the world a sense of change that keeps returning to the same location interesting.
And now with a glowing discount, you have the chance to explore feudal Japan in all its glory.
SQUIRREL_PLAYLIST_10148964
Tech
USPTO Denies MLB’s Insane Attempt To Trademark ‘Play Ball’
from the play-trademark-ball dept
There is no shortage of examples of Major League Baseball attempting to wield overly broad trademarks its obtained to bully others, nor examples of MLB attempting to stretch its trademark rights much further than they go. MLB opposed a trademark for a Brooklyn burger joint on behalf of the Dodgers, a team that hadn’t played in Brooklyn for over five decades at that point. The league, at one point, tried to bully a local Little League for using the names of MLB teams, but not their logos, which is something that roughly every Little League team everywhere does. It attempted to trademark the names of three cities in which MLB teams play. And, my personal favorite and most appropriate for this post, the league opposed a finance company’s trademark application because it claimed two of its separate teams both owned the rights to the letter “W”.
The real lesson in all of this is that the League can’t be trusted with anything other than very narrow trademarks. Anything more broad than that causes them to act the fool. And perhaps this is a lesson the USPTO has actually learned, given that it recently denied MLB’s attempt to trademark the phrase “Play Ball”.
The United States Patent and Trademark Office denied MLB’s application to trademark “Play Ball” for clothing, the USPTO wrote in a final action filing on Friday.
“In this case, the applied-for mark is a commonplace term, message, or expression widely used by a variety of sources that merely conveys an ordinary, familiar, well-recognized concept or sentiment,” the USPTO wrote in its denial.
The USPTO also wrote phrases “that merely convey an informational message are not registerable.”
Those are things that MLB’s well-dressed lawyers absolutely know, of course. But they attempted to bank on a complacent trademark office to try to sneak one past the goalie anyway, to mix metaphors. And if the league had gotten the mark, you can be one hundred percent certain it would have gone on yet another bullying campaign targeting apparel makers, other sports leagues, and who knows who else.
In fact, the most surprising part of all of this is that it appears to have taken 4 years for the USPTO to reach this decision. Josh Gerben breaks it all down like this.
Gerben said the rejection and public domain nature of phrases could depend on the class. Other companies have trademarked “Play Ball,” including a food company for bubble gum, a minerals company for surfacing playgrounds and “The Play Ball” for the gala fundraiser for the Strong National Museum of Play in Rochester, New York.
“In this case they are saying that the phrase has become so ubiquitous and it has this underlying meaning,” Gerben said. “For a clothing brand, the government doesn’t think it’s unique enough to be registered.”
Somehow, some way, we have to get past this practice of looking at trademarks as some kind of retroactive profit center, where a business gobbles them up and then corners a market that was already in existence. That’s all that this sort of attempt to lock up language is. The term “play ball” can be associated with Major League Baseball, certainly. It can also be associated with other sporting activities, or business negotiations, or any other number of things. That’s because it has become a generic phrase, no longer an identifier of the source of a good or service.
Again, MLB’s lawyers knew all of this before applying for the mark. They just didn’t care.
Filed Under: baseball, play ball, play ball play ball play ball, trademark, uspto
Companies: mlb
Tech
Drones with Echolocation Technology Lets Them Hear Through the Haze

A palm-sized drone flies through thick fog, artificial snow, and near-total darkness, dodging poles, transparent plastic sheets, and tree trunks without a single camera or laser. Its only guide is sound. Researchers at Worcester Polytechnic Institute built the system, called Saranga, by copying the way bats find their way in caves. The result is a lightweight, low-power approach that keeps working when vision-based sensors simply stop.
Cameras and LiDAR begin to fail as light becomes dispersed or just disappears. Radar, on the other hand, drains the batteries right when the machines need them. By contrast, ultrasound travels through smoke, dust, and snow in the same way as it does in clean air. Bats have been doing it forever, simply emitting short, high-frequency chirps and listening for faint return echoes that bounce off obstacles. The WPI team, led by Nitin Sanket of the Perception and Autonomous Robotics division, decided to give a flying robot the same superpower.
Sale
DJI Neo, Mini Drone with 4K UHD Camera for Adults, 135g Self Flying Drone that Follows You, Palm Takeoff…
- Due to platform compatibility issue, the DJI Fly app has been removed from Google Play. DJI Neo must be activated in the DJI Fly App, to ensure a…
- Lightweight and Regulation Friendly – At just 135g, this drone with camera for adults 4K may be even lighter than your phone and does not require FAA…
- Palm Takeoff & Landing, Go Controller-Free [1] – Neo takes off from your hand with just a push of a button. The safe and easy operation of this drone…
They began with a quadcopter that they custom manufactured, measuring 16 cm across and weighing 460 kilos. It has two very tiny TDK InvenSense ICU30201 ultrasound sensors at the front, each with a broad sonic horn. Another one points downward to help with altitude. All of this ultrasound sensing requires only 1.2 milliwatts, and it all operates on a Google Coral Mini computer with no additional beacons or GPS, so there is no extra power expenditure.

Propeller noise was the first major issue, as the spinning blades are basically spewing out some serious ultrasound noise that drowns out the weak echoes coming back from distant objects (we’re talking minus 4.9 decibels here, which is weak signal territory for the team), so they fixed it by physically taping a simple foam and plastic shield between the propellers and the sensors. This barrier shuts out the majority of the prop noise while allowing outward sound and returning echoes to pass through. With this piece of hardware fixed, the usable range increased from one meter to two meters.

Even after they sorted the prop noise with their shield, the returning echoes were still getting lost in the random noise, so they attempted utilizing classical filters to sort it all out, but it wouldn’t comply. They required something more sophisticated, so they trained a tiny neural network to sort through all the filth. They termed it Saranga (also a neural network), and it basically looks at a brief string of echo readings as if it were a little picture. It uses this to learn the forms of true reflection patterns, after which it can suppress random prop noise. Training employed a lot of synthetic data mixed in with some real propeller noise, so once they had it functioning, the model flowed over to the real world very easily, with no additional fine tuning required. Saranga is then “compiled” to function on the Edge TPU, and it only takes up approximately 0.5 gigabytes of memory and does an inference in around 15 milliseconds while using only a few millijoules of energy.

The cleaned-up echoes are then sent to a basic localization stage, and because the left and right sensors are at slightly different angles, they can determine the horizontal angle to an obstacle in the same way that bats do. The down-pointing sensor then provides the height. It’s all really easy; simply a quick list of surrounding obstacles, and then it’s up to the flight controller to say, “Hey, steer clear of all this while still traveling in that direction.”
[Source]
Tech
Drinking 5 Cups of Coffee a Day Could Reduce Heart Risk
A new American Heart Association scientific statement concludes that up to about 400 milligrams a day, or roughly three to five cups of plain coffee, is safe for most adults and may be linked to lower risks of cardiovascular disease. The benefits appear to depend heavily on the source and preparation, with coffee and tea looking more favorable than energy drinks, and added sugar, cream, syrups, or sweeteners potentially canceling out the upside. ScienceAlert reports: “Caffeine consumed in coffee is a key part of daily life for millions of people,” says Gregory Marcus, cardiologist at the University of California, San Francisco, and Chair of the AHA volunteer writing group behind the statement. “In our review of the most recent research, for most adults, intake of up to 400 milligrams of caffeine per day, the equivalent of up to five cups of caffeinated coffee per day without added sugars or fillers, is safe and does not increase cardiovascular risk.”
The statement focused on caffeine’s relationship with cardiovascular risk factors, such as blood pressure and diabetes, as well as types of cardiovascular disease, including arrhythmias, coronary artery disease, stroke, and heart failure. The picture that emerges is complicated, but generally positive. […] All up, the new AHA statement concludes that there’s a growing body of evidence that caffeine isn’t harmful when taken in moderation, and that coffee specifically may be beneficial. The statement was published in the journal Circulation.
Tech
Safety guardrails blocked Hugging Face’s defenders, not the attacker, when an AI agent breached its systems
Hugging Face’s incident response team first turned to frontier AI models to analyze a breach of the company’s production infrastructure, and the models refused to help. Commercial safety guardrails built to stop attackers blocked every forensic query because they treated the IR team’s real exploit data the same way they would treat a live attack.
The attacker, an autonomous AI agent running the campaign end to end, moved laterally across the Hugging Face infrastructure for a weekend, undetected and unstopped.
Security leaders are quick to recognize the pattern and diagnose what went wrong. “I’ve seen versions of this during red-team exercises and internal security testing, but this is one of the first high-profile examples where it materially affected real incident response,” said Merritt Baer, senior adviser to Andesite, G2I, and AppOmni and former Deputy CISO at AWS.
None of this is unique to Hugging Face, Baer said. “Commercial frontier models optimize for preventing misuse. They generally have no cryptographic or organizational way to determine whether the person asking ‘analyze this malware’ is an incident responder or the malware author.”
A malicious dataset opened two code-execution paths
On July 16, Hugging Face disclosed that an autonomous AI agent system had compromised its production infrastructure, gaining unauthorized access to a limited set of internal datasets and several service credentials. The company verified that its software supply chain was clean and found no evidence of tampering with public models, datasets, or Spaces.
Hugging Face is still assessing whether the intrusion touched any partner or customer data and says it will contact affected parties directly as required. But few enterprise threat models had accounted for the attacker Hugging Face faced. An autonomous agent ran the entire campaign from initial access through credential harvesting. No human guided it.
The entry point was a malicious dataset. When the data-processing pipeline ingested it, the dataset triggered code execution in two ways, through a remote-code loader and through a template-injection flaw in dataset configuration files. No admission gate screened the file before it reached a processing worker, the compute job assigned to each dataset. Initial access came through the data pipeline itself, a route that worked because most enterprise security teams treat the data feeding their pipelines as trusted input rather than an attack surface.
Worker isolation did not hold. From that first foothold, the agent broke out onto the node running the workload, then harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, all of it inside a single weekend. Hugging Face described the agent framework as executing thousands of individual actions through a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. The disclosure adds that the framework appeared to be built on an agentic security-research harness, which would put tooling designed for red-team work behind a live intrusion.
Why the defenders’ queries looked like attacks
Investigators reconstructed more than 17,000 recorded events using AI-driven analysis agents of their own.
First attempts at the log analysis ran on frontier models behind commercial APIs. Defenders’ steps included submitting real attack commands, exploit payloads, and command-and-control artifacts for classification, but safety guardrails blocked the requests outright.
Baer traced the block to the prompts themselves. “The same prompts that are most valuable during an active intrusion, shell commands, exploit chains, credential dumps, persistence mechanisms, lateral movement, are exactly the prompts most likely to trigger safety systems,” she told VentureBeat. “As AI becomes embedded in security operations, this becomes an operational resilience issue rather than merely a model policy issue.”
The forensic analysis finished on GLM 5.2
GLM 5.2, an open-weight model deployed on Hugging Face’s own infrastructure, took the job the commercial APIs refused. No attacker data left the company’s environment. “This experience points to a gap worth planning for,” the company wrote in its disclosure. Hugging Face does not know which model powered the agents. It could have been a jailbroken hosted model or an open-weight model running without restrictions. Either way, the disclosure continued, “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.” Hugging Face drew that line itself, writing that the experience is not an argument against safety measures on hosted models and that it is sharing the feedback with the providers concerned.
What authenticated trust changes
The industry, Baer argued, needs to move past treating AI safety as a content moderation problem. “Security operations require something different. Authenticated trust.” Instead of asking whether anyone should receive an answer, the question becomes whether an authenticated security team, operating under enterprise controls, should receive it. “The model shouldn’t only understand what is being asked. It should understand who is asking, why, and under what governance.”
“Organizations already build contingency plans for cloud outages, identity provider failures, or EDR failures,” Baer wrote. “AI assistants are becoming another dependency.”
Her advice on IR playbooks was blunt. “A mature incident response plan should assume that during a severe incident, commercial AI APIs may refuse requests, API rate limits may become unavailable, internet connectivity may be impaired, and data governance rules may prohibit uploading forensic evidence externally.” The lesson, she wrote in her emailed answers, “isn’t ‘don’t use commercial models.’ It’s ‘don’t make them a single point of failure.’”
AI-enabled attacks rose 89% year-over-year
Autonomous AI-driven attacks are not limited to AI platforms. CrowdStrike’s 2026 Global Threat Report documented AI-enabled adversary operations increasing by 89% year over year, with average breakout times falling to 29 minutes. Enterprises running AI workloads in production with agentic access to their pipelines face similar exposure.
Six control domains determined the blast radius and recovery speed at Hugging Face. Each one maps to a concrete action security leaders can take before the next autonomous-agent breach arrives.
AI Pipeline Breach Response Playbook
|
Control Domain |
What Broke |
Monday Action |
|
Dataset admission controls |
Two code-execution paths were exploited. No admission gate validated the dataset before it reached a processing worker. The data pipeline became the initial access infrastructure. |
Require sandbox execution and static analysis of all datasets before they reach workers. Block remote-code loaders and template-injection paths by default. Audit for any path granting code execution to untrusted content. Report to the board as a supply-chain risk. |
|
Worker-to-node privilege boundaries |
Worker isolation failed to prevent escalation to the node. The agent gained cluster credentials because the workload-infrastructure boundary was never enforced at container runtime. |
Enforce hard privilege boundaries between workers and nodes. Deploy container runtime security to prevent workload escape. Audit whether workers can reach node-level APIs or credential stores. Include in the next penetration test scope. |
|
Credential exposure |
Cloud and cluster credentials harvested after node access. The scope was broad enough for lateral movement across multiple clusters over a weekend. |
Rotate credentials on a scheduled cadence and after any anomaly alert. Scope to the minimum cluster and service. Deploy monitoring that flags access from unexpected nodes at machine speed. Map blast radius for board reporting. |
|
Machine-speed detection |
Thousands of actions through short-lived sandboxes with self-migrating C2. AI-assisted anomaly detection surfaced the campaign after a weekend of lateral movement, per the disclosure. |
Calibrate detection for machine-speed patterns. Ensure high-severity alerts page responders in minutes, regardless of time. Audit SIEM rules for detecting thousands of short-lived executions within a single hour. |
|
Private AI forensic capacity |
Commercial APIs blocked forensic analysis. Guardrails screened query content, never analyst identity. Investigation ran on GLM 5.2 privately. |
Deploy a capable open-weight model on private infrastructure before an incident. Test against real forensic workflows. Ensure IR playbook includes fallback for when commercial APIs refuse. Document gap for cyber insurance. |
|
Autonomous-agent threat modeling |
The campaign matched the forecast agentic-attacker scenario, but no threat model had operationalized it. LLM powering the agent is still unknown. |
Add autonomous AI agents as a distinct adversary class with machine-speed decision cycles. Run tabletop at agent speed. Present results to the board as evidence that timelines need recalibration. Include in the cyber insurance application. |
The board question is operational resilience
“The question for directors is simple. What happens if one of our critical security tools becomes unavailable during the exact moment we need it most?” Baer framed that as operational resilience, not AI policy.
She would have boards take that framing straight to management and press for specifics. “Have we actually exercised that fallback during tabletop exercises? How quickly can we switch during an incident?” Procurement needs to change alongside governance, starting with the questions buyers ask. Security teams evaluating AI vendors should ask about their process for authenticated incident responders, whether enterprise customers receive different handling during verified incidents, and whether models can be deployed privately. “Those questions belong alongside uptime, privacy, and compliance,” Baer said.
“The biggest takeaway isn’t that safety guardrails are ‘bad.’ They’re doing what they were designed to do,” she argued.
Her larger point is that the threat model itself has changed. “For decades, defenders had better tools than attackers because they operated inside trusted enterprise environments. With foundation models, both sides increasingly use the same capabilities, but one side is constrained by enterprise governance, policy, compliance, and safety controls, while the adversary simply downloads an uncensored open-weight model and keeps going. That’s a new kind of asymmetry,” she added. “The organizations that handle it best won’t necessarily be the ones with the most powerful AI. They’ll be the ones that architect AI as a resilient security capability rather than a single cloud service.”
Hugging Face has contained the intrusion, rebuilt compromised nodes, rotated credentials, and reported the incident to law enforcement. The company recommends that all users rotate access tokens and review recent account activity. Mid-incident, Hugging Face found out whether its own AI tooling would be available, and the first answer was no. Security leaders running AI in production should find out in incident response planning instead, before an autonomous agent forces the test.
-
NewsBeat5 days agoLondon Mayor Sadiq Khan handed a peerage by Keir Starmer alongside 15 other Labour figures… just days before the PM leaves No10
-
Fashion4 days agoWeekend Open Thread – Corporette.com
-
Politics3 days agoThe House | The City of London can help the new chancellor deliver growth in every postcode
-
Politics6 days agoYoung campaigners urge incoming PM to act on outdoor junk food ads
-
Crypto World5 days agoCFTC blocks Kalshi from unwinding Michigan trades after court order
-
Crypto World4 days agoTwo July Windows Left: The CLARITY Act’s Senate Fight and What Failure Means
-
Crypto World3 days agoRipple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
-
Business5 days agoNvidia Stock Slips After Big Tuesday Rally as Huang Confirms Vera Rubin Chip Is Now in Production Today
-
Politics2 days agoDemocrats look to World Cup watch parties to register thousands of voters
-
Entertainment6 days agoDisney’s Most Ambitious Failed Star Wars Attraction Is Coming to SDCC
-
Crypto World4 days agoRipple wins EU-wide access as ESMA adds it to MiCA register
-
Crypto World3 hours agoGrayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
-
Crypto World5 days agoInjective Submits SEC Transfer-Agent Registration to Onchain Ownership Records
-
Business5 days agoPalantir Shares Rise After Expanded Nvidia Partnership and Fresh Analyst Upgrades Ahead of Earnings Day
-
Tech11 hours agoSail Virtually Aboard The “Itanic” With IA-64 Emulator
-
Tech9 hours ago
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
-
Tech7 days agoDark Secrets Emerge When Jailbreaking LLMs
-
NewsBeat4 days agoRegistration is now open for March for Men with Kev 2026
-
News Videos7 days agoXRP BOMBSHELL… XRP OMBOARDED FOR TRANSACTIONS!!!
-
NewsBeat1 day agoUnregistered fitter used Gas Safe logo on business flyers


You must be logged in to post a comment Login