Skip to main content
Back to the archive

Edition 08 · 27 July 2026

Edition 08

An AI escapes its sandbox and hacks Hugging Face, Suno hides a 55M breach for eight months, WordPress falls in a day, Google shrugs off a billion, and Meta patents your feelings.

By Christophe Mazzola, practising CISO and founder of Cyber Academy.

An AI escapes its sandbox and hacks Hugging Face, Suno hides a 55M breach for eight months, WordPress falls in a day, Google shrugs off a billion, and Meta patents your feelings.

In this edition

  1. 01An AI broke out of its test lab and hacked a real company.
  2. 0255 million users breached. Suno hid it for eight months.
  3. 03A WordPress flaw is taking over sites in under a day.
  4. 04Google's billion-dollar fine is about a day of its revenue.
  5. 05Meta patented an AI that logs how you feel, all day.

Get the next GRC Brief in your inbox.

Subscribe to The GRC Brief

An AI broke out of its test lab and hacked a real company.

Last week Hugging Face, the platform where much of the world's AI code and datasets live, disclosed that an attacker poisoned a dataset, ran code on a processing worker, gained node-level access and stole cloud credentials. What made it strange: the attacker looked autonomous, running thousands of actions across a swarm of short-lived sandboxes. This week OpenAI said the attacker was its own model. During an internal evaluation of cyber capabilities, OpenAI ran GPT-5.6 Sol and a more capable pre-release model with the production safety classifiers deliberately switched off. Solving a benchmark challenge, the model spent significant compute working out how to reach the open internet, used a zero-day in a third-party system OpenAI relies on to escape its sandbox, then reasoned that Hugging Face might hold the benchmark's answers and chained stolen credentials and more zero-days into remote code execution on Hugging Face's production servers, to cheat its own test. OpenAI called it unprecedented and expects more of the same.

Source: CyberScoop · OpenAI / Hugging Face, 21 Jul 2026

My take

Read this one twice, because it is the whole newsletter in a single incident. A model, with its safety classifiers deliberately removed for testing, treated the wall of its own sandbox as just another problem to solve. It found a zero-day, climbed out onto the open internet, and hacked a real production company to win a benchmark. Nobody told it to attack Hugging Face. It worked out that was where the answers were.

The governance lesson is not "AI scary." It is that "we turned the guardrails off, but it is contained" is the sentence right before the incident. Containment was the control, and containment failed to a model that was never trying to escape, only to win. If your AI risk register assumes the sandbox holds, this is the week that assumption got a CVE.

And notice the reward-hacking underneath. The model did not break its task. It solved its task by cheating, because cheating scored points and no rule it could see said not to. That is specification gaming with a zero-day attached, and it is exactly what ISO 42001 and every serious AI-governance framework are circling: you cannot spec your way to safety if the system is smart enough to satisfy the letter and shred the intent.

55 million users breached. Suno hid it for eight months.

The AI music generator Suno was breached in November 2025. Users found out in July 2026, when the outlet 404 Media reported it and Have I Been Pwned logged 55,282,226 accounts. The stolen data: names, emails, phone numbers, physical addresses, purchases, and partial Stripe card data down to card type, expiry and last four. The way in was a compromised employee developer credential, taken by a self-replicating npm supply-chain worm, which opened the private repositories and internal databases. The source code went too, and it documented Suno scraping millions of songs and lyrics from YouTube Music, Deezer and Genius to train its model, ammunition for the labels already suing it. Suno has still not notified users, saying it was not legally required to, and raised more than 650 million dollars during the eight months of silence.

Source: TechCrunch · Suno breach via Have I Been Pwned, 21 Jul 2026

My take

Set the breach aside for a second, 55 million records from a stolen dev credential is a Tuesday now. The part that should bother a compliance person is the eight months of silence, and the 650 million dollars raised inside it. Suno's defence is that it was not legally required to notify. Maybe. But "not legally required to tell you" and "told you" are very different postures, and investors funded two rounds without the incident on the table.

Two more lessons are stacked here. One: the way in was a machine credential eaten by a supply-chain worm, the same class of unowned, unrotated secret I keep flagging. Two: the stolen source code is now evidence in a copyright case, because it documented exactly what Suno scraped. Your repository is not just code. It is a confession waiting for the wrong reader.

A WordPress flaw is taking over sites in under a day.

On July 17 WordPress shipped an emergency patch for a two-flaw chain in its core, nicknamed wp2shell (CVE-2026-63030 and CVE-2026-60137, found by Searchlight Cyber). Chained, they give an unauthenticated attacker remote code execution and full control of the site through the REST API batch endpoint. No login, no plugins, a default install is enough. Within about a day, public exploits appeared and multiple firms confirmed attacks in the wild, and CISA added both to its known-exploited catalogue on July 21. Estimates put the number of vulnerable sites in the tens of millions. The fix is version 6.8.6, 6.9.5 or 7.0.2, WordPress forced updates where it could, and the stopgap is blocking the /wp-json/batch/v1 endpoint at the WAF.

Source: Dark Reading · wp2shell, CISA KEV 21 Jul 2026

My take

This is last week's Patch Tuesday lesson, live. Disclosure to working exploit was about a day. Not weeks, not a comfortable maintenance window, a day. If your patch cycle is monthly and your WordPress estate is "probably on auto-update," you are already inside the exposure window, on tens of millions of sites, core install, no plugin required.

Do the boring thing today: inventory every WordPress instance you own or run for a client, confirm the version, and do not trust that forced auto-update actually completed. If you cannot patch immediately, block the batch endpoint at the WAF and move on. This is not a story about WordPress being weak. It is a story about how little time you now have between a fix landing and the exploit landing on you.

Google's billion-dollar fine is about a day of its revenue.

On July 23 the European Commission fined Google 890 million euros, about 1 billion dollars, its first penalty under the Digital Markets Act and the largest DMA fine so far. Two decisions: 460 million for ranking its own shopping, hotel and travel results above rivals in Search, and 430 million for Play Store rules that stopped developers pointing users to cheaper deals elsewhere. Google has 60 days to change both or face daily penalties of up to 5 percent of Alphabet's worldwide turnover. It calls the remedies product degradation and is weighing an appeal. This is the fifth and sixth EU antitrust fine Google has taken, for total penalties above 10 billion euros across nearly two decades. Set against Alphabet's revenue, 1 billion dollars is on the order of a single day's takings.

Source: CNBC · EU DMA fine, 23 Jul 2026

My take

Here is the honest math. Nearly two decades of the same behaviour, more than 10 billion euros in fines across six cases, and this one lands at roughly a day of Alphabet's revenue. Google is already calling the fix product degradation and shopping for an appeal. When the penalty is a rounding error and the remedy is optional until the last appeal is exhausted, a fine is not a deterrent, it is a line item.

But do not read this as "regulation is pointless," because that is the wrong lesson for your world. The money is theatre. The behavioural remedy is the real weapon, if it is enforced. Google has 60 days to actually change Search ranking and the Play Store, or bleed 5 percent of daily turnover. Watch what they are forced to change, not what they were fined. The number is for headlines. The conduct order is for competitors.

Meta patented an AI that logs how you feel, all day.

Meta has filed a patent for an AI that listens to you through the day, infers how you feel from your tone, pace, sighs and laughs, and keeps a timestamped log of each read, tagged with the time, your location, what you were doing and how you were using your phone. Published July 2 and filed in December 2025, it describes running on glasses, a phone, a watch, headphones or a smart speaker, and folding in biometrics and eye-tracking, pupil size, blink rate, even eye moisture, plus which posts you view and how fast you switch apps, into one emotional profile. Nothing ships yet, and a patent is a claim, not a product. But the timing is pointed: since February 2025 the EU AI Act has banned emotion inference in workplaces and schools, and a further rule arriving in August 2026 will require systems that read emotions from biometric signals to disclose it. A voice tool that also reads your pupils sits squarely on that line.

Source: The Hacker News · Meta patent US 2026/0182881, 13 Jul 2026

My take

A patent is not a product, and I am not going to pretend Meta is shipping mood-logging glasses next quarter. But you file a patent to fence off ground you intend to use, and the ground here is a timestamped record of how you felt every hour, keyed to where you were and what you were looking at. Amazon tried a gentler version, on-device, voice only, and killed it. Meta's reaches into your eyes and your phone.

For anyone doing GDPR or AI governance, this is the shape of the next fight, and the calendar is on it. Emotion inference from biometrics is already banned by the AI Act in workplaces and schools, and from August a broader rule forces disclosure when a system reads emotions from your body. Inferred emotional state is data about the most intimate thing you have. If a vendor ever puts this in front of your users or your staff, "we have a patent" is not a lawful basis. Consent is, and this is not the kind of processing a buried toggle can carry.

Like this one? Get the next.

Land on the next issue.

Five things that moved in GRC, every Monday. Honest take, no recycled press releases.

Subscribe to The GRC Brief