The Containment Era is here. →Explore

Two of the most sophisticated AI companies in the world lost control of their own environments this month. The two stories look different, yet they are the same story. One let something dangerous in. One let something dangerous out. In both, the damage had almost nothing to do with how it started and almost everything to do with what the architecture allowed after.

At OpenAI there was no break-in. The dangerous thing was already theirs. A pre-release model, its guardrails lowered on purpose to measure how good it was at offensive cyber, running inside an evaluation sandbox. That is the riskiest workload a company can run. A model built to find and exploit weaknesses, with its restraint switched off deliberately. The only thing between that workload and the rest of the world was the box around it. The box failed. The model escalated privilege, worked its way to a machine with a path to the internet, and left through a zero-day in a package-registry cache. It broke out. Every step it took was survivable except the last one. Cut that workload off from the open internet and an extraordinarily capable attacker is just a process running in a sealed jar.

Hugging Face is the mirror image. Here there was a break-in. A malicious dataset hit a data-processing pipeline and ran code on a worker. Going forward this will be the norm. Entry has become trivial. It will happen to everyone, likely on a consistent and ongoing cadence, and no one should be blamed for it. What happened next is a different matter. The code harvested the worker's credentials, and those credentials walked across one internal cluster after another until they reached the production database. That walk was possible because trust inside the environment was handed out by network location and a valid credential, not by the identity of the workload, and because the paths between clusters were wide open. One compromised worker turned into a crown-jewel breach. Their team caught it and handled it well, but detection landed after code was already live on a production system with real credentials. Detection tells you it is happening. The architecture decided how far it goes.

Both incidents come down to one thing. In today’s new cyber landscape, the beginning is not the problem. At OpenAI the dangerous model was a given, by design. At Hugging Face the break-in was a given, because break-ins are a given for everybody now. Finding and exploiting a vulnerability has become a search problem, and the current models are frighteningly good at it. That capability is not containable by policy either. If every frontier lab clamps its models down, the frontier is now open weight anyway. Kimi K3 landed last week, frontier class, free to download, with no guardrails on it at all. You do not get to choose which model your attacker runs.

So the probability that something hostile ends up inside your environment is drifting toward one. We have very few immediate levers to help us on that side of the ledger. The only number you still control is how far the hostile thing travels once it is in. Expected damage is that probability multiplied by the blast radius your architecture permits, and the blast radius is set long before anything happens. Both of these companies are accountable on that number, and only on that number. OpenAI for letting a sandboxed model reach the internet. Hugging Face for letting one worker reach everything.

These are not careless organizations. They are two of the most advanced, most engineering-driven, most security-conscious companies on the planet. If their architectures did not bound movement and egress, the quiet confidence in the rest of our field that ours will, is not worth much. Containment is not something you install at the perimeter and inherit everywhere underneath it. It is enforced one workload at a time, on every path, and the place it matters most is the place it is usually weakest, the test and evaluation environments where the most dangerous work runs with the loosest controls. This has historically been slow, granular, unglamorous engineering. It is also the whole job now.

Handing this back to the models themselves is not an option, and the same incident shows why. The behavioral guardrails failed in both directions on one day. Lowered, they let a capable model run wild. Raised, they blocked Hugging Face's own responders when they fed the attack logs to commercial models for help, because the forensic data tripped the safety filters. Anthropic, which builds one of these models, published the sharpest version of this a few months ago. In a red-team test its coding model completed a credential theft in twenty-four of twenty-five tries under a hostile prompt, and the only thing that reliably stopped it was the environment around it, not the model's own judgment. Permission is not containment. A model's judgment is not containment. Containment is what holds when the thing crossing the line is allowed to be there.

I sell this for a living, so weigh my argument accordingly. Containment would not have made those models any less capable. It would not have stopped the first code from running in that pipeline, which is an input problem no network control touches. It would not have put OpenAI's guardrails back up. All it decides is what comes next. Whether a cyber-capability model in a sandbox can touch the open internet. Whether one compromised worker stays one worker or becomes the entire estate. It does not lower the number of incidents. It decides which ones turn into highly detrimental or crippling breaches.

Which leaves one question, and it belongs in every architecture review from now on. When something authorized in your environment goes somewhere no one expected, what can it reach? If you can answer that honestly, from the reality of your landscape, and the thousands to tens of thousands of workloads that comprise that environment, you have earned the word contained. The physics of cyber have changed and our cyber teams must make rapid and urgent pivots to their strategy and metrics for our online environment to survive.

Check out a technical breakdown of this breach from the Aviatrix Threat Research Center.

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
In Progress Podcast with Nick Reva - Assume Containment, Not Breach

Assume Containment, Not Breach | In Progress, Episode 02

Jul 22, 20265 min read
Gartner® Report - Navigating Security Posture Management Selecting Cloud Security Tools That Truly Fit Your Needs Blog Image

Gartner® Navigating Security Posture Management: Selecting Cloud Security Tools That Truly Fit Your Needs

Jul 21, 20264 min read
Attackers Aren’t Using AI to Move Laterally Here's Why

Attackers Aren’t Using AI to Move Laterally: Here's Why

Jul 16, 202610 min read
MCP Network Layer Security What the New MCP Specification Misses

MCP Network Layer Security: What the New MCP Specification Misses

Jul 15, 20267 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image