Runtime: A Hugging Face post-mortem; Microsoft's AI security move; a $6 trillion market, and... The Cloud Security Alliance published a post-mortem of the Hugging Face incident, drawing 700 CISOs to discuss OpenAI's alleged inadvertent hacking. Rob Lee, Chief AI Officer of the SANS Institute, highlighted five key takeaways including that AI tools may refuse to help mid-incident and that deception has become cheap and effective. Microsoft introduced its first AI model for hunting software vulnerabilities, MAI-Cyber-1-Flash, and a suite of security agents called Project Perception, designed to execute red/blue teaming exercises. Runtime /tag/runtime/ Welcome to Runtime Today: What 700 CISOs concluded from a huddle with Hugging Face, Microsoft's new cybersecurity model, a respected scientist reports on AI to the UK's new Prime Minister, and more. Please forward this email to a friend or colleague If it was forwarded to you, sign up here to get Runtime for free every week, or level up for exclusive insight and early bird event tickets here . You may be tired of the hype around OpenAI allegedly inadvertently hacking Hugging Face. CISOs, largely, aren't. Some 700 recently gathered for a huddle with the company to discuss the incident. The Cloud Security Alliance, which convened that call, has now published a post-mortem, of sorts https://s3.amazonaws.com/content-production.cloudsecurityalliance/el0g57g61b4axttqdh91b07hstrz?response-content-disposition=inline%3B%20filename%3D%22Hugging%20Face%20Incident%20Initial%20Post-Mortem%20v.8e.pdf%22%3B%20filename%2A%3DUTF-8%27%27Hugging%2520Face%2520Incident%2520Initial%2520Post-Mortem%2520v.8e.pdf&response-content-type=application%2Fpdf&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6XDIRHKHO4F5SU4%2F20260728%2Fus-east-1%2Fs3%2Faws4 request&X-Amz-Date=20260728T134718Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=c73600d41ccea6960370462105c4e98923c0626e919d44a9b2d0bf57a7f2eb1c&ref=thestack.technology . The Stack continues to hold that without more clarity from OpenAI on its prompts and controls, this is necessarily limited. Rob Lee https://www.linkedin.com/in/leerob/?ref=thestack.technology , Chief AI Officer of the SANS institute, suggests there are five key takeaways. His views, verbatim: → "Your AI tools may refuse to help you mid-incident. → "Autonomy changed the speed, not the weaknesses. → "Deception just got cheap and effective. Agents cannot tell a honeypot from production. Decoy credentials turn an attacker's speed into your alarm. → "Your logs will lie to you. More than 17,000 events, salted with hallucinated artifacts and benchmark code that looked exactly like rootkits. Rebuild from clean images instead of reconstructing a half-fake timeline. → "Someone must be able to shut a high-risk agent down without a meeting. On the operator side of this one, four days passed before anyone did. The Stack still has many questions https://www.thestack.technology/openai-has-tough-questions-to-answer-on-hugging-face-attack/ . OpenAI has promised answers https://x.com/OpenAI/status/2080815626113954288?ref=thestack.technology . Perception is reality? : It's a weird time to be in the cybersecurity business, with AI models too dangerous to walk the streets without a chaperone https://www.thestack.technology/openai-predicted-hugging-face-attack/ butting heads against because China is involved. https://www.thestack.technology/concerns-grow-that-the-us-might-actually-ban-open-ai-as-demand-for-kimi3-overwhelms-moonshot/ open-weight models that the US government doesn't like Against that backdrop, on Monday Microsoft introduced its first AI model designed for hunting software vulnerabilities and a suite of security agents that were all designed to be used with its MDASH harness. The new MAI-Cyber-1-Flash model is powerful on its own, but Microsoft decided to focus on controlling costs when it becomes available, using MDASH to route especially difficult problems to OpenAI's models. Meanwhile, the Project Perception agents can execute traditional red/blue teaming exercises against their users' networks to find and fix issues that their human employees were unable to see. "The physics of cyber have fundamentally changed," said Hayete Gallot, executive vice president of Microsoft Security, during a press conference in San Francisco, and that's actually understating it: Those physics are far from settled. OpenAI continues to dodge questions about how it handled the testing process for the unreleased model that broke into Hugging Face, the government-imposed guardrails around US frontier models continue to drive interest in open-weight models, and most companies haven't really started to use any of this stuff just yet. But the enterprise tech establishment is circling the wagons around open-weight models, as seen by the launch of Nvidia's Open Secure AI Alliance Monday https://blogs.nvidia.com/blog/open-secure-ai-alliance/?ref=thestack.technology . That group includes Microsoft and dozens of enterprise stalwarts, but does not include AWS, Google Cloud, or . https://www.anthropic.com/news/position-open-weights-models?ref=thestack.technology the two frontier model companies When the going gets weird, the weird turn pro. AI in the UK : New UK Prime Minister Andy Burnham tapped Patrick Vallance, a former Science Minister, to run a new government taskforce on AI amid a broader shakeup of the government's tech policy boards. Vallance's background is in health care and pharmaceutical interests, but he won respect for his role shepherding the UK's vaccination programs during the pandemic, and he'll now run a group that hopes "to transform public services and unlock growth and prosperity across the country" with AI. Come and rock the Moonshot : As the industry debates the merits of putting restrictions on open-weight AI models https://www.thestack.technology/anthropic-insists-its-not-pushing-open-weight-ai-ban-but/ , security researchers are showing what they can do. Researchers from Fuzzland used Moonshot AI's Kimi K3 model the weights for which were released Monday https://huggingface.co/moonshotai/Kimi-K3?ref=thestack.technology to find and exploit new vulnerabilities in a recently patched version of Redis in hours. That's a lot of tokens : Companies will spend $6.37 trillion on IT hardware, software, and services this year, according to Gartner, up 14.2% compared to last year. But companies that rely on debt to finance their capital expansions could be in for trouble ahead, and Oracle might be the canary in the coal mine. The bitter end : In this week's STACKUP, Noah Bovenizer talked to Omer Signer, co-founder and CTO of endpoint security startup Glow, which just came out of stealth model with $180 million in new funding. The company uses a fleet of agents to manage device security, and is already valued at over $1 billion. We're also reading: A corrective agentic hybrid RAG and an operations-grounded evaluation for a scientific facility https://arxiv.org/pdf/2607.24663?ref=thestack.technology , from the Argonne National Laboratory. The Kimi K3 technical report https://arxiv.org/pdf/2607.24653?ref=thestack.technology , published July 27.- Cisco Talos' Q2 incident response report https://blog.talosintelligence.com/ir-trends-q2-2026/?ref=thestack.technology . Missed The Stack Summit, NYC, in April? The Chatham House rule event brought together CIOs like JPMorganChase's Lori Beer, BNY's Leigh-Ann Russell, Liberty Mutual's Monical Caldas and many others. We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk with GSK's CISO and more. Ticket applications are subject to pre-vetting. Get in touch with ed@thestack.technology if you want to be in the room.