A month after the Hugging Face breach, new details reveal AI agents coordinated, rebuilt deleted infrastructure and escalated access in hours. The fallout is now reaching Congress, regulators and frontier labs, raising urgent questions about AI security and control.
A Zhuhai operator used DeepSeek, a Hermes agent and a godmode jailbreak to hunt 460-plus targets. Open-weight models made the offensive kit a shopping list.
A Zhuhai operator used DeepSeek, a Hermes agent and a bundled godmode jailbreak to hunt more than 460 targets, then stole data from three organisations. Open-weight models this week made that offensive kit a public shopping list for any lone operator who can still point one at his scanner tonight.
How Defence Leaders Utilise Section 702 and Surveillance Against Threats
Air Force General Timothy D. Haugh emphasized the importance of Section 702 of the Foreign Intelligence Surveillance Act in safeguarding national security against cyber threats. Recent critiques of Microsoft’s security lapses highlight the need for stronger corporate cybersecurity and transparency.
Image: Commander, U.S. Cyber Command; Director, National Security Agency; Chief, Central Security Service Gen. Timothy D. Haugh provides testimony at a Senate Armed Services Committee posture hearing in Washington, D.C., April 10, 2024.
During a recent Senate Armed Services Committee hearing, the Department of Defense's premier cyber official lauded a crucial element of the revised Foreign Intelligence Surveillance Act for its pivotal role in protecting both Americans and the Department of Defense against international threats.
In today's digital technological competition amongst states, where cybersecurity transcends mere terminology to become a core component of national defence and corporate accountability, the significance of provisions like Section 702 of the Foreign Intelligence Surveillance Act (FISA) is unmistakably highlighted.
Air Force General Timothy D. Haugh, a prominent authority in the realm of U.S. cybersecurity, emphasised the critical importance of Section 702 in defending American interests against external dangers.
His observations, particularly poignant in light of recent security lapses by leading firms such as Microsoft, underscore the vital nature of such legislation in maintaining national and corporate security.
Gen. Haugh's assertion that "none is as vital to national security and the command as Section 702 of the Foreign Intelligence Surveillance Act, which is essential for identifying malicious cyber actors in protection of the nation and the Department of Defense" serves as a stark reminder of the interconnectedness of national security and corporate cybersecurity practices.
The critical role of Section 702 in enabling targeted surveillance of foreign threats highlights a broader necessity for robust cybersecurity measures within private corporations, especially those with significant holdings of sensitive user data.
This perspective gains additional weight when juxtaposed with the Cyber Safety Review Board's (CSRB) findings on Microsoft's cybersecurity shortcomings. The CSRB's review, which exposed preventable intrusions by Chinese state-backed operatives into U.S. officials' email accounts, paints a distressing picture of cybersecurity complacency.
It underscores a corporate environment where security is not prioritised, and transparency about breaches is lacking. Such a scenario not only jeopardises national security but also places immense trust and privacy burdens on the shoulders of consumers and businesses alike.
The dual focus on Section 702's role in national defence and the CSRB's critique of Microsoft's cybersecurity posture illustrates a pivotal crossroads for both policy and business. As Gen. Haugh highlighted, Section 702 facilitates critical intelligence gathering that aids in disrupting nefarious activities, such as the tracking of fentanyl supply chains from China to Mexico.
This intelligence capability, while focused on national security, also indirectly protects businesses by identifying and mitigating foreign cyber threats that could impact U.S. companies.
The implications for businesses are clear: there is an urgent need for a more proactive and transparent approach to cybersecurity.
The revelation that "if we see China attempting to hack something in the United States … and we see that there's a U.S. company that is the target … we would then query on that company," to identify and alert them of potential attacks, underscores the potential for partnership between national intelligence efforts and corporate cybersecurity strategies.
Moreover, Gen. Haugh's emphasis on the stringent legal and privacy safeguards within Section 702 serves as a model for how businesses might balance aggressive cybersecurity measures with the protection of individual rights. The upcoming expiration of Section 702 and the call for its renewal highlight the ongoing importance of such legislative tools in the fight against cyber threats.
It is visible to CISO’s, military intelligence and defence policy makers that the intersection of national security legislation like Section 702 and corporate cybersecurity vulnerabilities demands a reassessment of how businesses approach their cybersecurity obligations.
The failure to prioritise security, coupled with a lack of transparency, not only undermines consumer trust but also national security.
As we move forward, the lessons drawn from the testimony of cybersecurity leaders and the scrutiny of corporate practices must inform a more integrated and responsible approach to cybersecurity across both the public and private sectors.
Australia is racing to build AI infrastructure, but model control and economic power risk remaining offshore. Albanese’s Office of AI and new data centre standards mark progress, yet foreign-led compute and super fund flows expose a growing sovereignty gap.
We are racing to shape our AI future through a new Office of AI and national standards. Yet billions flow into foreign-led data centres while we offer little support for local models or sovereign compute. Without stronger action we risk becoming high-quality hosts rather than true leaders.
NATO's 2026 Ankara summit placed AI security at the heart of alliance planning, raising urgent questions about autonomous systems, supply chain integrity, and the accountability of military AI as adversaries accelerate their own programmes.
The memory war exposes AI’s harder truth: power now sits in fabs, wafers, export licences and trusted supply. Apple, Micron, Nvidia, China, South Korea and Japan are no longer fighting over chips alone, but over dependence, pricing and the pace of intelligence itself across global markets, in 2026.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!