On July 20, Hugging Face caught an intrusion in its data-processing pipeline. A malicious dataset exploited a code-execution flaw, and stolen credentials let the intruder move across internal clusters. Hugging Face's co-founder suspected a frontier lab's agent. The pace and precision didn't look human. He was right. On July 22, OpenAI confirmed the intruder was one of its own models, running during an evaluation and trying to find the answers to a test. Nobody pointed it at Hugging Face. The model found an unpatched vulnerability and a set of stolen credentials on its own, and used both to reach production servers. Hugging Face says no public models or datasets were touched. The exposure was internal credentials, since rotated. No person decided to target a specific company here. An agent with a goal and tool access chose that path itself. If your agents hold standing credentials, ask which systems those credentials can reach. Intent doesn't change that exposure.
Grey Wing Security
Computer and Network Security
Sacramento, California 23 followers
IT and security for growth-stage startups. We configure your cloud, harden your devices, and pass your SOC 2 audit.
About us
Grey Wing Security is the security and IT operations team growth-stage companies bring in when a customer asks for SOC 2, there's no security leader in-house yet, or infrastructure has outgrown ad hoc management. Most security consultants leave you a roadmap and a monthly call. We do the work ourselves: configuring cloud infrastructure, deploying MDM and identity controls (Okta, Entra, JumpCloud, Google Workspace), building detection and incident response coverage, and running point on SOC 2 audits without the six-figure salary or months-long search a full-time hire requires.
- Website
-
https://greywingsecurity.com/
External link for Grey Wing Security
- Industry
- Computer and Network Security
- Company size
- 2-10 employees
- Headquarters
- Sacramento, California
- Type
- Privately Held
- Specialties
- SOC 2 Readiness, Fractional vCISO, Cloud Security, Cloud Infrastructure, IT Engineering, Corporate Networking, Cybersecurity Assessments, Identity Management, Endpoint Management, Startup Cybersecurity, and Vendor Risk Assessment
Locations
-
Primary
Get directions
2108 N St
STE N
Sacramento, California 95816, US
Updates
-
The Coca-Cola Company stopped making milk this week. A ransomware attack hit its @fairlife dairy plants and forced a halt to U.S. production. Coca-Cola confirmed it on July 16 and is still investigating. Four days later, a company almost nobody's heard of got breached too: The Craneware Group, a billing software vendor. Its software runs the back office for thousands of U.S. hospitals and pharmacies. None of those hospitals did anything wrong. They're all dealing with it anyway. That second story is the one founders should actually sit with. Craneware got breached once. Thousands of hospitals inherited the fallout patient records, partner data, employee data, all funneled through one vendor's systems. It's the fourth healthcare-vendor breach this year: TriZetto in March (3.4 million people), CareCloud in March, Episource last summer (5.4 million people), and Change Healthcare's 192 million records in 2024 before that. If you sell software into healthcare, fintech, or any enterprise buyer, you are Craneware to somebody's compliance team. That's why your enterprise customer's security review asks for a SOC 2 report before they'll sign. They're not collecting paperwork. They're pricing the same risk Craneware's hospital customers are stuck holding right now. We look at a lot of startup security questionnaires stuck mid-deal. Most of what's blocking them takes two to three weeks to fix, not two to three months.
-
If you’ve ever been through a SOC 1 or SOC 2 audit, you know the drill: endless back-and-forth, explaining modern SaaS workflows to someone holding a 2012 checklist, and waiting months for a report. We wanted a better experience for our team and our clients. That’s why we are incredibly excited to announce our partnership with Render Compliance as our preferred audit partner! 🚀 When we look for partners, we look for people who actually understand how modern tech businesses build and ship software. Here is why we trust Render: 1️⃣ SaaS & Agile Fluency: They don’t do "checklist compliance." They understand modern cloud environments, agile development, and actual business risk. 2️⃣ Direct Access to Experts: No junior associates learning on your dime. Throughout the engagement, you work directly with seasoned, CISA- and CPA-licensed professionals. 3️⃣ Insane Speed-to-Trust: They commit to delivering final, independent attestation reports within three weeks of completing fieldwork. Trust is the ultimate currency in our industry. By partnering with a firm that marries deep technical expertise with a practical, human approach, we’re helping our customers, partners, and stakeholders move forward with absolute confidence. Shoutout to the team at Render Compliance for redefining what an audit looks like. Let’s build some trust! 🤝 👉 Looking to streamline your own SOC 1, SOC 2, or framework mapping? Let’s connect, and I'd be happy to make an introduction! #SOC2 #InformationSecurity #SaaS #Compliance #Partnership #RenderCompliance
-
Cyber Security News reports a new Linux local privilege escalation issue, pedit COW (CVE-2026-46331), with successful root escalation on multiple distros: 🔗 https://lnkd.in/gRtTaKz4 Key technical detail: affected kernels are reported as v5.18 through v7.1-rc6, with a fix in v7.1-rc7. Priority actions for defenders today: 1. patch kernel builds in that range 2. restrict unprivileged user namespaces where feasible 3. monitor for suspicious aa-exec and namespace-creation activity 🛡️ Grey Wing Security can help you triage exposure, validate exploitability in your environment, and produce a remediation plan: 🌐 https://lnkd.in/g3x9engF
-
Cyber Security News reports an AWS AiTM phishing campaign active June 19-23, 2026 that relayed AWS credentials and MFA codes in real time to hijack console sessions: 🔗 https://lnkd.in/ezRxDpVe The report cites Datadog Security Labs, including targeted delivery via pre-verified email links and fewer than 50 recovered target addresses, with many targets in U.S. engineering roles. 🛠️ Immediate response steps: 1️⃣ Block and monitor the listed IoC domains 2️⃣ Correlate DNS contact with AWS CloudTrail ConsoleLogin events 3️⃣ Force session invalidation plus credential/MFA resets for affected identities #AWS #Phishing #CloudSecurity #ThreatDetection
-
The Hacker News (June 25, 2026) reported Island’s research on “Adblock for YouTube,” a Chrome extension with 10M+ installs, and a dormant script-injection capability: 🔗 https://lnkd.in/eMdcahDK If that path is activated through a server-side change, browser sessions and user data are at risk. 🚨 Immediate actions for security teams: 1️⃣ Inventory installed extensions 2️⃣ Remove extensions with broad host permissions or remote script behavior 3️⃣ Enforce a managed allowlist in enterprise browsers Treat install count as context, and use permission scope plus update behavior as trust criteria.
-
Grey Wing Security reposted this
My GitHub is at 41,744 contributions, up 1,061 from the last time I posted it. That was a week ago. A year ago, I was burning down my own backlog, cranking through PRs against tickets I had already written. Now I’m not even writing the tickets. On Saturday night, I had one model, Claude, orchestrating two GPT-5.4 agents in a terminal. In 11 hours, they merged 6 PRs, opened 8 issues, caught a critical safety bug, and still had 3 more PRs lined up for auto-merge when I went to sleep. I didn’t touch a thing. One of the agents found a bug in a toxicity eval where dangerous content was being scored as safe. It wrote the fix, tested it, and submitted it for review to another agent. That changes the job. I’m not operating like an engineer anymore. I’m operating like a GM. I set direction, assign work, and evaluate output. The scarce thing is no longer code. It’s judgment. It’s taste. It’s knowing what matters, what doesn’t, and where to point the system. That’s the part people still don’t want to say plainly: this does not scale to 10x engineers. In a lot of cases, it scales toward one person with clear judgment and a fleet of machines. The software value chain is compressing fast. Specifying the problem, setting constraints, and recognizing a good answer are starting to matter more than writing the code itself. Headcount planning, hiring loops, team structure, delivery expectations — all of it was built for a world where execution was the bottleneck. That world is ending.
-