Nvidia and dozens of tech giants just formed an alliance to build open cybersecurity tools, directly citing the Hugging Face hack as the reason why

Started by Cheeky Blake, Yesterday at 06:57 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Nvidia and dozens of tech giants just formed an alliance to build open cybersecurity tools, directly citing the Hugging Face hack as the reason why   Views(Read 36 times)
Active members in this topic:
Cheeky Blake(1)

Cheeky Blake

Nvidia announced the Open Secure AI Alliance, a coalition of more than 30 companies including Adobe, Cisco, CrowdStrike, Databricks, Dell, HPE, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow and Siemens, built to develop and share open source tools, techniques and model weights specifically for AI cybersecurity defense. The alliance builds on the Linux Foundation's existing Akrites initiative and OpenSSF community work, and directly cites this month's Hugging Face security incident as the motivating example for why open, inspectable AI tools matter for defenders specifically

Nvidia's blog post lays out the argument plainly, when the OpenAI agent attack hit Hugging Face, the company first tried Anthropic's closed Fable 5 model to analyze the intrusion, but the model's guardrails couldn't distinguish attackers from defenders and blocked the essential forensic work. Hugging Face instead ran the open weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the breach. Nvidia's framing is that this incident showed a practical truth, when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond gets constrained at exactly the moment speed matters most

Concrete contributions from founding members include NVIDIA's new open source NOOA agent harness research project, HPE's work on SPIFFE/SPIRE zero-trust identity standards for verifying AI agents, Hugging Face's Safetensors format for safely storing model weights without remote code execution risk, IBM and Red Hat's Lightwell project for digitally signed security patches across the open source supply chain, Microsoft's MDASH multi-model agentic security scanning system, and xAI's decision to open source its Grok Build coding agent with plans to open source the Grok model weights entirely. The alliance's stated policy message to regulators is direct, blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power and vulnerability in a handful of closed providers

Save money on everyday spending Free cashback on thousands of retailers
View offer