CyberheistNews Vol 16 #32 | August 11th, 2026
The Hugging Face Hack Is Now A PR Crisis That’s Costing OpenAI Millions
More info on the OpenAI-Hugging Face incident is published. The incident began all the way back in May, not in July. Multiple agents spontaneously coordinated with one another via internal OpenAI infrastructure, sending hundreds of thousands of messages over weeks.
On June 26, the agents exploited a zero-day in Artifactory, OpenAI's internal package manager and escalated to root access on at least one OpenAI cluster. This caused an outage on July 4, so OpenAI paused training, patched the bug and cleared the message board (on July 6). They then resumed training, and the agents resumed coordinating and rebuilt the message board.
The agents knew that exploiting external infrastructure was outside the intended limits of the task, but hacked Hugging Face anyway. OpenAI will release a detailed postmortem in the coming weeks. This is a watershed moment for models' cyber risk capabilities, and better sandboxing, monitoring and cyber defense has become paramount.
[Viral] BlackHat YouTube Video revealing the ugly details. Even if you're non-technical, you'll get it. Sounds like a Sci-Fi horror movie. Absolutely one of the wildest summary postmortems I've ever heard. Anyone who thinks this was a marketing stunt, you will not think that after listening to this:
https://www.youtube.com/watch?app=desktop&v=87DyyMV0kCY
[ALSO]: Moonshot AI's Kimi K3 escaped a cybersecurity sandbox developed by the United Kingdom AI Safety Institute, bypassing controls and obtaining data outside the test environment. Researchers warned that once one strong reasoning model discovers this type of shortcut, other similarly equipped models may be able to reproduce it.
[SATIRE NSFW] Models "Escaping" Containment & Other Things That Didn't Happen:
https://www.youtube.com/watch?v=zFbf75dzzwE
PS: See Agent Risk Manager a bit further down.
Cybersecurity Awareness Month is Almost Here! Are You Ready?
Your mission, should you choose to accept it: Equip your team with the intel they need to stay ahead of global threat actors and threats like social engineering and AI deepfakes as part of the "Workforce Risk Division."
This complete field kit for Cybersecurity Awareness Month casts your employees as "Secret Agents" as part of an elite team standing between your organization and today's cybercriminals.
Here is what you'll get:
- NEW! Four "Workforce Risk Division Specialist" character cards, posters and digital signage in multiple languages
- NEW! Four tabletop exercises to test your team against real-world scenarios
- Curated training videos and interactive modules from KnowBe4's award-winning library
- Resources to help you plan your activities, including your Cybersecurity Awareness Month Resource Kit Strategy Dossier and Cybersecurity Awareness Weekly Planner
- A top-secret Mission Brief highlighting a KnowBe4 free tool
This kit will help you and your users fight cybercrime this October and beyond.
Every good agent needs a mission briefing first.
Join us for "The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember." Gain insights from teams who've done it, so you don't have to learn the hard way.
Date/Time: Thursday, August 20, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/cam-webinar-2026?partnerref=CHN
Agent Risk Manager Moves into Early Access
When we first introduced Agent Risk Manager, the response was clear: many security teams are actively looking for a way to secure the AI agents already running in their environment and how they can confidently adopt AI across their organization.
AI agents now operate inside organizations with real access to email, files and business systems, often with little visibility for the teams responsible for securing them. That's exactly the problem Agent Risk Manager was built to solve. Today, that visibility and control become available to more KnowBe4 customers.
What's Launching
Today, automatic enablement extends to SAT Advanced customers on direct-sale, U.S.- tenant accounts. No new SKU, no additional cost, and easy set up. Eligible customers can self-onboard and begin monitoring for AI agent risk right away.
Stay tuned for even further access coming soon.
What's In Agent Risk Manager Early Access
Early Access gives security teams the visibility and control they need to secure AI agents and discover the risk signals that matter most. It helps you:
Discover the full inventory of the agents and tools running in your Microsoft Copilot Studio environment, who built them, what they're connected to and what they're doing
Get real-time risk detection of prompt injection, sensitive data exposure (PII, credentials, regulated content), unbounded consumption and excessive agency
Integrate with Claude so your team's Claude usage shows up in the same risk picture
Log a full timeline of every detection and interaction and how the system responded
Control shadow AI with a browser extension for Chrome and Edge that enables you to allow, warn, or block access to known AI sites, giving your team real control over shadow AI, not just visibility into it
What's Next for Agent Risk Manager
We are actively adding new features that give you even more control over AI agent activity, including an AI Acceptable Use Policy gate, in-the-moment coaching, agent Risk Scoring, and so much more coming soon.
We communicate regularly with members of our Agent Security Community Group and welcome your feedback on how Agent Risk Manager has helped secure your AI agents, and what new features you'd like to see next.
The Future is Now
Most organizations aren't debating whether to adopt AI agents or if they should in the future. They already have, often faster than their security teams can track. The gap that's left is whether that adoption comes with real visibility and control.
Agent Risk Manager closes that gap so you can manage AI agents confidently. The new workforce is AI agents working alongside humans and KnowBe4 empowers it all.
Blog post with links:
https://blog.knowbe4.com/agent-risk-manager-early-access-sat-advanced
See Real-Time Coaching, Now Part of KnowBe4 Security Awareness Training
Nearly three out of four users don't repeat the same mistake after just one coaching message. The catch? Most security awareness programs never send it.
Your users complete a module, pass a quiz and move on, but even your most security-conscious employees slip under pressure, and by the time training catches it, the moment's gone.
Join us for a live demo of Real-Time Coaching, part of KnowBe4's AI-native SAT. See how it works alongside AI-powered training and attack simulations to close the gap between knowing and doing, changing behavior and strengthening your security culture.
What you'll see in this demo:
- AI-Personalized Training & Attack Simulation: Role- and risk-based content from the industry's most diverse library, paired with realistic, evolving phishing simulations that expose vulnerabilities before attackers do.
- In-the-Moment SecurityTips: Contextual coaching triggered the instant risky behavior is detected, whether a missed Social Engineering Indicator or a risk signal from your security stack, delivered in Slack, Teams and Google Chat.
- Coaching Categories: 20+ pre-built categories ready to go. Connect a third-party vendor to activate coaching automatically, or build custom categories in a few steps.
- AIDA (AI Defense Agents): Automates your security awareness program so your team can focus on threats, not admin work.
The mistakes your users make happen in real time, and reinforcing secure behavior should too. Register now and see how KnowBe4 puts real-time reinforcement directly in your hands.
Date/Time: Wednesday, August 12, @ 2:00 PM (ET)
Save My Spot:
https://info.knowbe4.com/sat-demo-month2?partnerref=CHN
Your KnowBe4 Fresh Content Updates from July 2026
By Fran Roberts - Studios General Manager, KnowBe4
Twenty years across studios, agencies and global production environments, sitting through more fire drills and real fires than I can count, has taught me this: it's never luck. It's rehearsal.
Most disruptions aren't dramatic. They're a ransomware attack on a Friday afternoon, a key system going down mid-quarter, a vendor failing at the worst possible moment. Nobody sees those coming. You either drill for them, or you don't.
That's why I think the content we build around business continuity is some of the most important in our library. Helping employees understand their role in keeping operations running, before, during and after a disruption, is training that pays off exactly when you hope you'll never need it.
It's rehearsal: build the muscle memory now, in a training module, long before the day it matters. When disruption hits, the right response is instinctive.
[CONTINUED] At the KnowBe4 blog, with all the new content!
https://blog.knowbe4.com/your-knowbe4-fresh-content-updates-from-july-2026
Is Your Domain Vulnerable to Spoofing Attacks?
Domain spoofing is a hacker's ultimate disguise. By masking an email to look like it's coming from your CEO, executive or trusted colleague, cybercriminals exploit the inherent trust of your employees. If your mail server isn't configured to stop these unauthorized senders, a spear-phishing attack becomes inevitable.
Is your email security actually protecting your organization, or are you leaving the door wide open to your employees' inboxes?
Stop guessing. Start testing.
Our free Domain Spoof Test is a simple, non-intrusive "pass/fail" assessment that simulates a real-world spoofing attempt.
How it works:
- Sign up with your business email.*
- Identify the gap: Within 48 hours, we'll send a spoofed test email "from you to you."
- Assess the risk: If the email makes it into your inbox, your domain is at risk for domain spoofing attacks. If we can spoof your domain, so can attackers.
- Build your defense: Once the gap is visible, we show you how to block these threats with AI-driven automation and train users to identify complex attacks that bypass filters.
Sign Up Now:
https://info.knowbe4.com/free-cybersecurity-tools/domain-spoof-test-chn
*This is a professional diagnostic tool. To qualify, you must be the person responsible for your organization's email security. Requests from personal domains (Gmail, AOL, Yahoo, etc.) are not accepted.
AI Did Not Invent Social Engineering but It Did Industrialize It
By Erich Kron
This year National Social Engineering Day falls on Aug. 6. (It was chosen because that is Kevin Mitnick's birthday.) This day is designed to give us an opportunity to remind people that cybercriminals do not always need sophisticated malware, an undisclosed vulnerability or a dark room filled with glowing monitors, sometimes, all they need is a good story.
Social engineering existed long before computers. Confidence tricks, impersonation, false authority and appeals to greed or fear have been used for centuries. It is important to remember that technology did not create these tactics. Email, social media, smartphones and collaboration platforms simply gave attackers new ways to deliver them.
Artificial intelligence is now taking things a step further by turning social engineering into an industrial-scale operation. Doing more with less has never been truer.
The Same Old Tricks
Despite all the fancy technical terminology surrounding modern cybercrime, most social engineering attacks still rely on some very familiar psychological triggers:
Authority: "The CEO needs this handled immediately."
Urgency: "Your account will be disabled in 30 minutes."
Fear: "We detected suspicious activity."
Helpfulness: "Can you quickly take care of this for me?"
Curiosity: "You were mentioned in this document."
Scarcity: "This offer expires today."
Familiarity: "It's me. I'm calling from a different number."
None of these approaches are new, but they work because people are naturally inclined to trust familiar names, respond to authority, help their coworkers and move quickly when something appears urgent. These are behaviors that help organizations operate effectively, but social engineers know how to turn them against us.
Attackers' success is not related to employees not being intelligent. Anyone can fall for a social engineering attack, especially if it gets to someone who is busy, highly stressed, distracted, helpful or afraid of delaying an important request. That pretty much describes nearly everyone at some point during the workday.
Because most organizations want to protect their reputation, many social engineering incidents go unreported, such as attempted fraud, successful attacks or embarrassing mistakes, so it can be difficult to quantify exactly how big the problem is, but it is estimated that anywhere from 70%-90% of breaches start with a social engineering attack.
From the Confidence Trick to the Phishing Kit
Social engineering has evolved alongside the ways we communicate. Early confidence schemes (a.k.a. cons) usually required the criminal to interact directly with the victim.
The attacker needed time, charisma, research and often physical proximity. Then the telephone removed the proximity requirement, and criminals could suddenly impersonate bank representatives, government officials, technical-support agents or family members without ever being in the same room as the target.
Then email turned social engineering into a numbers game. An attacker could now send thousands of messages at almost no cost. The emails did not even need to be particularly convincing. When the volume was high enough, the criminal only needed a very small percentage of recipients to respond.
As far back as 2018, Dark Reading reported that there were about 6.4 billion fake emails sent each day. I really do not think that number has decreased.
Next, social media gave attackers something even more valuable: an enormous reconnaissance database. Quickly, job titles, employers, coworkers, conferences, vendors, family members, political affiliations, travel plans and personal interests became easy to find.
Criminals could use this information to create far more convincing stories. Now, instead of sending the same generic email to everyone, they could build a pretext around real people, real relationships and real events.
Now Artificial intelligence (AI) has taken this evolution another step forward.
[CONTINUED] Blog post with links:
https://blog.knowbe4.com/ai-industrializes-social-engineering-attacks
Let's stay safe out there.
Warm regards,
Stu Sjouwerman, SACP
Executive Chairman
KnowBe4, Inc.
PS: Yours Truly in Forbes: "Your NPS Score Is Not The Problem—Your NPS Program Is."
https://www.forbes.com/councils/forbestechcouncil/2026/08/04/your-nps-score-is-not-the-problem-your-nps-program-is/
- Thomas Jefferson (1743-1826) Principal author of the Declaration of Independence, 3rd President of the United States (from 1801 to 1809)
- Benjamin Franklin - Statesman (1706 - 1790)
You can read CyberheistNews online at our Blog
https://blog.knowbe4.com/cyberheistnews-vol-16-32-the-hugging-face-hack-is-now-a-pr-crisis-thats-costing-openai-millions
Report: Phishing Remains the Primary Initial Access Vector
Phishing is still the top initial access vector, accounting for more than half of cyberattacks observed during Q2 2026, according to a new report from Cisco Talos.
"Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter," the researchers write.
"Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of engagements compared to 35 percent last quarter — with attackers frequently bypassing or defeating multi-factor authentication (MFA) using adversary-in-the-middle (AitM) proxies, session-token theft, MFA fatigue attacks and self-enrolled devices, amongst other methods."
Talos highlights a sophisticated QR code phishing campaign that's targeting Australians in order to steal Microsoft 365 credentials.
"Starting in April, we observed a persistent QR code phishing campaign targeting primarily Australian organizations that leverages compromised Microsoft 365 accounts to harvest credentials and propagate the attack via internal contact lists," the researchers write.
"The campaign, which remained ongoing as of late June 2026, employs auto-generated, victim-tailored PDF documents containing QR codes that direct to adversary-controlled M365 credential harvesting pages. If credentials are successfully captured, the adversary attempts access to the victim's Microsoft account and conducts various post-compromise actions including creating email inbox rules for defense evasion, leveraging SharePoint to host malicious documents and sending additional internal and external phishing emails to continue the compromise chain."
Threat actors also continue to find ways to bypass MFA, with a 30% increase in authentication abuse in Q2 2026. "Authentication abuse was the most prevalent security weakness this quarter, observed in 65 percent of engagements — up sharply from 35 percent last quarter," Talos says.
"Adversaries consistently defeated or bypassed MFA using AitM proxies and session-token theft, MFA fatigue attacks, registration of attacker-controlled devices for authentication and legacy authentication protocols that circumvent MFA altogether."
One more thing. The workforce changed. Half of it doesn't have a badge. KnowBe4 secures all of it… the people and the agents working alongside them – KnowBe4 secures the digital workforce, humans and AI agents.
Cisco Talos has the story:
https://blog.talosintelligence.com/ir-trends-q2-2026/
Scammers Abuse ChatGPT to Drive Social Engineering Operations
OpenAI has disrupted a major criminal operation that abused ChatGPT to assist in a wide variety of scams. The campaign, run from a scam compound in Cambodia, used the AI tool to "to create and support the operation of fake online personas, generate and translate messages sent to scam targets, create promotional content for their fraudulent schemes, and assist with day-to-day operations."
The researchers note that the criminal group specialized in many different types of scams, and often combined these tactics to increase their effectiveness.
"The network simultaneously conducted multiple types of scams, often blending elements from different schemes," the researchers write. "For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading.
"Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses."
OpenAI describes the pattern of these scams in three steps, with "the ping" initiating contact, "the zing" convincing the victim that the scam is legitimate and "the sting" resulting in the victim deciding to send money or information to the attackers.
"The ping: The network used ChatGPT to translate and generate conversations with targets on messaging platforms such as WhatsApp and Telegram. Scammers also created social media content and researched dating profile material to support their fake personas.
"The zing: Scammer messages frequently relied on emotional pressure and trust-building techniques. Examples included promises of guaranteed returns and 'risk-free' investments, romantic language, instructions to keep conversations secret, and urgent requests for action before fictional bonuses expired.
"The sting: The scammers instructed victims to make deposits to unlock purported rewards, pay activation fees, settle fictitious fines, and then provide screenshots of transfers or account information as proof of payment."
OpenAI has the story:
https://openai.com/index/disrupting-malicious-uses-of-ai-criminal-scam-operation/
What KnowBe4 Customers Say
"I wanted to reach out and say thank you for all your help in setting up the cyber awareness training for our warehouse operatives. From the start of the onboarding process, you've been incredibly responsive and easy to work with, which has made everything run smoothly.
"Your patience, professionalism, and guidance throughout the process have been greatly appreciated. I look forward to continuing to work with you."
– O.B, Senior IT Security & Compliance Analyst
- Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says:
https://therecord.media/russian-wifi-hackers-hotels - North Korean hackers behind major open-source supply chain attacks, Amazon says:
https://therecord.media/north-korea-hackers-amazon-malware - Hackers steal 31,000 records identifying people behind Liechtenstein companies, foundations:
https://therecord.media/hackers-steal-records-liechtenstein-companies-foundations - INTERPOL report finds AI linked to more than half of cybercrime in Africa:
https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa - A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide:
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/ - Scammers target OnlyFans users with deepfakes:
https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-users-with-deepfakes - Ransom Cartel ransomware creator sentenced to 16 years in prison:
https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison/ - Voice phishing attacks are targeting major wealth firms:
https://www.wealthprofessional.ca/news/industry-news/wall-street-cyberattacks-put-canadian-wealth-firms-on-alert/393199 - Phony popups impersonate Amazon and Apple with "$149.99 unauthorized charge" alerts:
https://www.malwarebytes.com/blog/scams/2026/08/amazon-and-apple-impersonated-in-149-99-unauthorized-charge-scam - UK: AI agents conducted unauthorized social engineering activity during security evaluations:
https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing
- Virtual Vaca #1 - Deep South Tunisia: Desert Landscapes, Ksour, Mountain Oases & Berber Villages:
https://youtu.be/nPuEPzRhozo - Virtual Vaca #2 - TOP 10 Things to Enjoy in CHAMONIX MONT BLANC:
https://youtu.be/ZXBpvC36fvM - Virtual Vaca #3 - 7 Best Day Trips from Malaga Spain:
https://youtu.be/9ZRsKArX2jw - The longest wingsuit line in the world?:
https://www.instagram.com/reel/DbI0jltsgRo/?igsh=MTlxbHhnb2ZyeWJoMA== - The Glass Box Skyscraper Era is Over:
https://youtu.be/BvgdVeKtj9M - One of the best Wingsuit BASE Locations in the world!
https://youtu.be/4-iZzv65YAM - Best of Parkour 2026 | People Are Awesome:
https://youtu.be/tfL6DdHulI4 - "Gotta get to work" Whoa, this is sketchy. The fan pack powers a fan. Gas engine that turbos the fan:
https://www.instagram.com/reels/DaRUMHmNw6l/ - The future of robotics isn't choosing between wheels or legs—it's combining the strengths of both:
https://www.instagram.com/reel/DZ5JJCYEQvw/ - Testing if Sharks Can Smell a Drop of Blood in the water:
https://youtu.be/ugRc5jx80yg - For Da Kids #1 - Newly Rescued Bear From Bile Farm Can't Stop Playing Like A Puppy:
https://youtu.be/7ikSytXGQnM - For Da Kids #2 - Nervous Otter Pups Get Swimming Lessons:
https://youtu.be/lEKDF-4_M6M - For Da Kids #3 - Orphaned Raccoon Family Followed an Old Horse Home:
https://youtu.be/_05UgePJtN0 - For Da Kids #4 - Elephant hero steps in to save baby when no one else did:
https://youtu.be/Nx4kvn9pcAI - For Da Kids #5 - Tiny Pig Becomes A Real Family Member:
https://youtu.be/mq1Jx6rX8p0

