Updated July 28, 15:31 BST with a functioning link for the CSA report.

Welcome to Runtime! Today: What 700 CISOs concluded from a huddle with Hugging Face, Microsoft's new cybersecurity model, a respected scientist reports on AI to the UK's new Prime Minister, and more.

Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up for exclusive insight and early bird event tickets here.

You may be tired of the hype around OpenAI allegedly inadvertently hacking Hugging Face. CISOs, largely, aren't. Some 700 recently gathered for a huddle with the company to discuss the incident.

The Cloud Security Alliance, which convened that call, has now published a post-mortem, of sorts. (The Stack continues to hold that without more clarity from OpenAI on its prompts and controls, this is necessarily limited.)

Rob Lee, Chief AI Officer of the SANS institute, suggests there are five key takeaways. His views, verbatim:

→ "Your AI tools may refuse to help you mid-incident.

→ "Autonomy changed the speed, not the weaknesses.

→ "Deception just got cheap and effective. Agents cannot tell a honeypot from production. Decoy credentials turn an attacker's speed into your alarm.

→ "Your logs will lie to you. More than 17,000 events, salted with hallucinated artifacts and benchmark code that looked exactly like rootkits. Rebuild from clean images instead of reconstructing a half-fake timeline.

→ "Someone must be able to shut a high-risk agent down without a meeting. On the operator side of this one, four days passed before anyone did.

(The Stack still has many questions. OpenAI has promised answers.)

Perception is reality?: It's a weird time to be in the cybersecurity business, with AI models too dangerous to walk the streets without a chaperone butting heads against open-weight models that the US government doesn't like because China is involved.

Against that backdrop, on Monday Microsoft introduced its first AI model designed for hunting software vulnerabilities and a suite of security agents that were all designed to be used with its MDASH harness.

The new MAI-Cyber-1-Flash model is powerful on its own, but Microsoft decided to focus on controlling costs when it becomes available, using MDASH to route especially difficult problems to OpenAI's models. Meanwhile, the Project Perception agents can execute traditional red/blue teaming exercises against their users' networks to find and fix issues that their human employees were unable to see.

Microsoft unveils new “Cyber Stack” AI agents and its first security-focused model
Project Perception is a collection of AI agents that can play both offense and defense for cybersecurity organizations.

"The physics of cyber have fundamentally changed," said Hayete Gallot, executive vice president of Microsoft Security, during a press conference in San Francisco, and that's actually understating it: Those physics are far from settled. OpenAI continues to dodge questions about how it handled the testing process for the unreleased model that broke into Hugging Face, the government-imposed guardrails around US frontier models continue to drive interest in open-weight models, and most companies haven't really started to use any of this stuff just yet.

But the enterprise tech establishment is circling the wagons around open-weight models, as seen by the launch of Nvidia's Open Secure AI Alliance Monday. That group includes Microsoft and dozens of enterprise stalwarts, but does not include AWS, Google Cloud, or the two frontier model companies.

When the going gets weird, the weird turn pro.

AI in the UK: New UK Prime Minister Andy Burnham tapped Patrick Vallance, a former Science Minister, to run a new government taskforce on AI amid a broader shakeup of the government's tech policy boards. Vallance's background is in health care and pharmaceutical interests, but he won respect for his role shepherding the UK's vaccination programs during the pandemic, and he'll now run a group that hopes "to transform public services and unlock growth and prosperity across the country" with AI.

Patrick Vallance put in charge of new UK AI taskforce
“An empowered unit, with clear accountability to the Prime Minister”

Come and rock the Moonshot: As the industry debates the merits of putting restrictions on open-weight AI models, security researchers are showing what they can do. Researchers from Fuzzland used Moonshot AI's Kimi K3 model (the weights for which were released Monday) to find and exploit new vulnerabilities in a recently patched version of Redis in hours.

Redis ships seven security releases after “27 minute” Kimi PoC
Public PoCs target stock Redis releases, including the newly patched 8.8.1. The authors say China’s Kimi K3 found 19 zero-days and built one exploit in 27 minutes.

That's a lot of tokens: Companies will spend $6.37 trillion on IT hardware, software, and services this year, according to Gartner, up 14.2% compared to last year. But companies that rely on debt to finance their capital expansions could be in for trouble ahead, and Oracle might be the canary in the coal mine.

IT will be a $6.37tn market this year, but AI bears are...
One frontier lab alone “roughly half” of Oracle’s $638 billion in RPO says S&P

The bitter end: In this week's STACKUP, Noah Bovenizer talked to Omer Signer, co-founder and CTO of endpoint security startup Glow, which just came out of stealth model with $180 million in new funding. The company uses a fleet of agents to manage device security, and is already valued at over $1 billion.

STACKUP: The Stack’s weekly tech startups and funding wrap
This week’s rounds and milestones.

We're also reading:

Missed The Stack Summit, NYC, in April? (The Chatham House rule event brought together CIOs like JPMorganChase's Lori Beer, BNY's Leigh-Ann Russell, Liberty Mutual's Monical Caldas and many others.)

We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk (with GSK's CISO) and more. Ticket applications are subject to pre-vetting. Get in touch with ed@thestack.technology if you want to be in the room.

The link has been copied!