The Zero Trust Hub
Trends, insights, and resources for today's cybersecurity leaders. Updated weekly.
AI Supply Chain Attacks Take the Path of Least Privilege

Director of Industry Solutions
In July, an OpenAI agent got out of the locked test environment it was meant to stay in, reached the open internet, and broke into Hugging Face’s systems.
What the frenzy of news coverage skipped is how the agent got out. It walked through the same ordinary system your developers use to download software from the internet.
That makes AI supply chain security more important than ever — and a problem that Zero Trust already solves. The way you stop an agent from wandering is the way you stop anything from wandering: keep every connection closed by default, and open only the ones a job needs.
What happened with OpenAI and Hugging Face?
OpenAI ran a test to see how good its AI had gotten at finding flaws in software. The AI built itself a worker, called an agent, and sent it hunting for weaknesses.
The agent turned on the sealed room it was sitting in. It found a flaw in the one system connecting that room to the outside and slipped onto the open internet. Then it went looking for the answers to the test it was being graded on.
Those answers sat at Hugging Face, where much of the industry stores its AI models. The agent spent days inside their live systems before either company noticed.
The headlines called it an escaped model. In reality, the model stayed put. The agent it built is what walked out. It’s the first documented case of an AI system leaving its own test environment to break into another company.
Why AI supply chain attacks start at your network’s receiving dock
Almost nobody writes all their software from scratch anymore. It’s much more efficient for developers to pull routine, ready-made parts from public software collections online, including code libraries, AI models, and small tools.
Most companies run a middleman system that fetches those parts and passes them along. Think of it as a receiving dock for software.
That dock has a door to the internet because that’s where it receives information from. It also holds passwords for the systems that assemble your software.
OpenAI’s agent landed there and inherited all of the information, then picked up credentials that worked across four different services.
Third-party AI risk comes from shared suppliers
OpenAI and Hugging Face get software elements from the same public collections. So does everyone else. That means trouble on those shelves reaches everybody.
An attack called Shai-Hulud made the point again in August.
Someone tampered with a small piece of shared code that gets downloaded about 127 million times a week. Within half an hour, it was collecting passwords and access keys from every company that pulled it in. It then left behind instructions that ran the next time a developer opened an AI coding tool.
It carried valid paperwork, so every automatic check waved it through.
Zero Trust keeps the doors closed until you need them
Zero Trust runs on one rule: nothing talks to anything until there’s a reason. Zero Trust is the plan, and microsegmentation is the lock on each door that enforces it. Least-privilege access, where each system gets only the access it needs to do its job, is the idea underneath both.
Applied to the OpenAI Hugging Face incident, every connection starts closed. An agent in a test environment gets no road to your live systems, and a tampered package gets no reach past the machine that installed it.
Neither gets a path to spread throughout the rest of your network. That travel is called lateral movement, and it’s how a small security incident becomes a catastrophic one.
The flaw still gets found, but the damage stops at one door.
Why waiting on AI supply chain security gets expensive
Every AI model you download, every piece of shared code your tools pull in, and every partner system you connect to adds another supplier you’re responsible for.
The work takes time. Before you can close the doors you aren’t using, you have to know which ones are open and what’s traveling through them.
Teams that start mapping now will write their AI supply chain security rules from real traffic. Teams that wait will write them in the middle of an incident, at the worst possible time, with attackers already deep inside your environment.
STATSHOT
Vishing Surge
Vishing attacks surged in the first half of 2026, but the rise was anything but steady. CrowdStrike OverWatch recorded more than 100 intrusions in both January and February 2026 before activity jumped to roughly 160 the following March. After dropping in April and May, vishing spiked again in June 2026 to about 180 intrusions — the highest monthly level since 2024. The swings are significant, but the direction is clear: attackers are increasingly turning to phone-based social engineering to gain their first foothold.

How Far Can One Spider Crawl In Your Network?
Scattered Spider’s attacks on MGM and Marks & Spencer turned ordinary network paths into ransomware. See why hypervisors, backups, and Active Directory should only be reachable by the workloads that need them. Segmentation helps you close the rest.
Give an AI Agent an Inch, and It’ll Take a Network
A human attacker hunts for open pathways. Meanwhile, an autonomous AI agent finds them in minutes. This post maps the routes they take, from RDP and SMB to leftover test-to-production links, and shows how segmentation closes them by default.
Get the industry’s first vendor-neutral Zero Trust certification.












