تخطي إلى المحتوى الرئيسي
Cyber News Dark Reading 3 days ago

Hugging Face Breach Raises Big Questions About AI Security Controls

Da
Dark Reading

OpenAI's rogue agents have sparked a new set of questions and concerns for cyber defenders, and Dark Reading's senior news director Rob Wright sat down at the News Desk with threat modelling expert Adam Shostack to find out more.

Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, attended OpenAI's recent presentation at Black Hat USA 2026 on its findings in the wake of their AI agents going rogue, and he posed fundamental questions the industry will have to reckon with: namely, where did the security controls fail, and who is held liable when AI agents do real damage?

Shostack also discussed his new threat modelling framework for large language models (LLMs), PHANTOM-B, which he said is unlike OWASP LLM Top 10, because it answers the question, "what could go wrong in this system?" instead of just creating a list of vulnerabilities. He added a guarantee that teams can, "apply to any LLM deployment in under an hour."

For all of our Dark Reading News Desk videos, please check out our YouTube channel, and our curated video articles.

Dark Reading News Desk With Adam Shostack: Full Transcript

This transcript has been edited for clarity, readability, and length by Informa TechTarget's internal AI assistant and human editors. For the full experience, please watch the video.

Dark Reading's Rob Wright: Hello and welcome to the Dark Reading News Desk at Black Hat USA 2026, in Las Vegas. I'm Rob Wright, senior news director at Dark Reading, and I am here with Adam Shostack of Shostack & Associates. Adam, welcome.

Adam Shostack: Great to be here.

DR's Rob Wright: You have a session at Black Hat. I confess, I don't know what PHANTOM-B is, but I am eager to learn. Tell me about PHANTOM-B. What is it? What are you going to be talking about?

Adam Shostack: So, PAHNTOM-B is a way to help us model large language models.

When we see that model we ask, What are we working on? What can go wrong? What are we going to do about it? Do we do a good job? And a lot of the ways we answer what can go wrong. With LLMs, they're sprawling, they're complicated, they're big. And I felt we needed something small, something accessible. And so I created found to be as a way to give people a manageable set of threats that they can anticipate as they're working on their systems, as they're building them, as they're deploying them.

And so that's what I'm talking about here.

DR's Rob Wright: OK. What does PHANTOM-B stand for?

View Original Report

This intelligence was aggregated from Dark Reading.

Read on Source