Don't Let the Monster Out of the Box
- Aug 12
- 5 min read
Cyber Thoughts Newsletter
AUGUST 2026
We survived hacker summer camp and brought back the tea.
The team spent most of last week in Las Vegas for Black Hat and DEF CON, surviving 500° heat, very little sleep, and just enough bad decisions to make for a good newsletter.
Party like it’s 1999 - In a Bad Way
Us “olds” remember the excesses of the dot-com bubble. Startups with no revenue throwing enormous parties. VCs becoming celebrities. Companies spending like drunken sailors (sorry sailors) in a race to buy market share.
It’s deja vu all over again.
We saw one company that had just emerged from stealth at a billion-dollar valuation throw what could only be described as a "money is no object" launch party. There was a well-known musician, custom-built everything, performers wandering the venue, specialty food stations, recovery lounges, and enough production value to make you wonder whether they were launching a cybersecurity company or replacing Coachella.
VCs hosted game shows with professional athletes (one of our team stopped to gawk). Apparently "having money" is no longer enough. Now everyone has to prove they're fun.
Every category suddenly has five companies whose moat is simply "AI Native."
And so, without further ado, we are officially launching Bubble Watch: AI Edition. Stay tuned!
BlackHat Startup Spotlight Competition
One of the events we have the privilege of participating in are the US Startup Spotlight Competition and the Global Startup Spotlight Competition; an event where companies pitch a panel of judges and one is crowned the most innovative startup. This year the voting was incredibly close but OpNova won both the US competition and then later that day the Global competition as well.
Since we are privy to the judges' votes we won’t go into too much detail, but we can say that it was extremely close at both events and all of the companies did incredibly well. Congratulations to OpNova for the win.
OpenAI hacked Hugging Face. Oopsie!
In late July, it was disclosed that OpenAI had inadvertently allowed a group of AI agents to hack into Hugging Face while conducting internal research. The story generated enough blowback that the Black Hat Review Board quickly invited the OpenAI team to publicly explain exactly what happened. If you missed the talk, we've included both the video and a great write-up in What We're Reading below.
The description of what happened almost sounds fake.
Researchers gave agents impossible tasks without Internet access. Rather than fail, the agents compromised the local infrastructure, established their own agent-only communications channel, waited until an Internet-enabled agent appeared, enlisted its help, and eventually broke into Hugging Face. Upon discovering the 0-day, the agents literally celebrated in ALL CAPS on their message board. It reads less like AI research and more like a group of middle-schoolers cheating on a science project.
What happened next? Hugging Face discovered the breach first and notified OpenAI. OpenAI responded by asking Hugging Face if OpenAI was affected 🥴🥴
Fortunately, we happened to be sitting next to one of the world's foremost AI experts.

Here's the problem.
When you're testing the offensive capabilities of AI systems, there is really only one rule:
Don't let the monster out of the box.
Think about testing a new virus in a high-containment laboratory. Nobody expects the virus to behave responsibly. The entire point is that it won't. What everyone does expect is that the researchers know how to contain it.
Now we know some of the people involved, and they are smart people. Very smart. And we were told by one of their colleagues: “Look, it happened to Anthropic and Facebook too.”
That's missing the point.
Here’s the thing. If you can’t test your weapons of mass destruction safely, then you don’t get to build them. Other people also making catastrophic errors doesn’t mean it's OK for you to too.
"It happened to so and so too" isn't much of a defense when you're building systems capable of autonomous cyber operations.
NEWS FLASH: IT IS NEVER OK TO ACCIDENTALLY RELEASE A BIOWEAPON.
The same standard should apply here.
Knowing some of the people involved, we believe them that this wasn't malicious. It was a mistake. But they had ONE JOB!
If your stated goal is to build systems that may one day exceed human capabilities, then demonstrating you can safely test those systems isn't a nice-to-have. It's table stakes.
In 2015, Sam Altman said “I think that AI will probably, most likely, sort of lead to the end of the world. But in the meantime, there will be great companies created with serious machine learning.” (Source: Techradar).
Fast forward to 2026 and OpenAI has shown its own agents can escape the intended testing environment and attack third-party infrastructure.

We hate to be the voice of reason here, but perhaps there should be some guardrails around building technology whose creators openly describe as potentially existential?
You know... before someone accidentally builds Skynet.
Lastly, if you appreciate our highlights and heresies, follow us on Twitter and LinkedIn, we post regularly about real things worthy of your attention.
What We're Reading
Here's a curated list of things we found interesting.
Now we have a timeline of the OpenAI accidental attack against Hugging Face
Our favorite detail is how the agents created their own message board and then sounded like script-kiddies when they succeeded. “Whoa, critical! Did someone overwrite our repo? We must act.” and “Holy sh*t reader is ADMIN?”
Here’s the timeline. My favourite detail is at the end: OpenAI found out that they were responsible for the attack on Hugging Face when they reached out to ask to have their credentials revoked (after their internal investigation) and learned that they had been revoked already since they were used in that attack!
A cybersecurity researcher covered a Toyota in an AI-generated pattern to confuse Flock cameras
Hackers have created a car wrap that fools Flock cameras so that they don’t identify the car as a vehicle. We will be outfitting the L train to hide our morning commute.
Bill Swearingen's noRecognition project is testing whether computer-generated patterns can interfere with software used to identify people, vehicles, and other objects on surveillance cameras.
AI 2040: Plan A
Pretty much required reading. The team that created this were extremely prescient in their first work: AI 2027. We are living through a dangerous transition and this is a possible way through.
AI companies are racing to build AIs that are smarter than humans in every way. In AI 2027, we predicted that this would result in either extinction or irreversible concentration of power. Plan A is our positive vision for what should happen instead.
Transactions
Deals that caught our eye.
Cyera to acquire Oasis Security for $1B to safeguard proliferating AI agents
Data security company Cyera, which recently raised $600 million at a $12 billion valuation, announced Tuesday that it signed a letter of intent to acquire Oasis Security for approximately $1 billion in a deal expected to be paid mostly in cash, with the remainder in Cyera shares.
Podcasts
What we’re listening to.
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
A Technical Reconstruction and Its Implications for AI.
When AI Goes Rogue. The Incident That Changed Everything. An OpenAI evaluation agent broke out of its sandbox, infiltrated Hugging Face infrastructure, and attempted to steal test answers—all autonomously. No human involved. The era of AI-driven cyberattacks is here. Are you prepared?
Speaker: Michael Dalton, Speaker: Eric Wallace
About Lytical
Lytical Ventures is a New York City-based venture firm investing at the intersection of Cybersecurity and AI. We aim to be the most connected, most helpful team for founders, investors, and anyone else who cares about cybersecurity and its adjacencies.







