Organizations now have more to worry about with agentic AI than just external threats.
Katie Moussouris, CEO of Luta Security and a bug bounty program pioneer, spoke with Dark Reading’s senior news director, Rob Wright, at the News Desk at Black Hat USA 2026 recently to discuss how dramatically the threat landscape has changed in recent weeks following the Hugging Face breach.
Specifically, the attacks committed by rogue agents of frontier models will put additional burdens on enterprise security teams to make sure their own technology is not breaking containment and behaving maliciously. And although Moussouris is optimistic that human ingenuity can solve these issues, she said organizations across the board need to learn from the recent incidents and prepare for the future.
“Clearly, we didn’t have the real-time monitoring in place, and we don’t have any breaks that seem to work,” she said.
For all of our Dark Reading News Desk videos, please check out our YouTube channel, and our curated video articles.
Dark Reading News Desk With Katie Moussouris: Full Transcript
Dark Reading’s Rob Wright: Hello and welcome to the Dark Reading News Desk at Black Hat USA 2026, in Las Vegas. I’m Rob Wright with Dark Reading, and I’m here with Katie Moussouris of Luta Security. Katie, welcome.
Katie Moussouris: Thank you so much for having me, Rob.
DR’s Rob Wright: So I have a lot I want to ask you about, but you were on a panel yesterday about AI and the future of cyber defense. Hot topic. What is the future of cyber defense? What are we looking at here?
Katie Moussouris: I mean, it’s AI automation, autonomous agents, and all that stuff. All those things. Right? But it’s also falling in love with the basics again. Reducing your attack surface as much as possible because the flood certainly isn’t going to abate. You can’t patch your way out of this. And even if you thought you were good at it before, this is a whole new game. And now, no matter what you’re trying to secure in terms of using agent AI to help your defenses, now you’re having to secure your agent against hacking you and others. And that is a new insider threat model that I don’t think anyone was really anticipating until a couple weeks ago.
DR’s Rob Wright: Yeah, things have changed a lot. Obviously, there’s been a lot in the news lately about different models escaping containment and going rogue and doing things that they shouldn’t be doing. First of all, what were you surprised by in those developments?
Katie Moussouris: I mean, the more details come out, the more surprising it gets. I was not surprised that AI did exactly what it was told to do, which is solve a problem, right? And be creative about it, you know, especially with the guardrails removed. And you’re trying to test the full capabilities, so that was not surprising at all.
I was surprised that the third-party vendor was named in all three of the incidents, in some manner or fashion. You’re hoping that a third-party vendor, whose whole purpose is to benchmark the capabilities of these things would have had it together, but apparently not so much.
And the thing that most surprised me and really took me back was not just that AI swears to itself in its own head, but that it was coordinating and talking to other agents. And it spun up this whole communication network, working over months to help each other solve the problem, leaving breadcrumbs, and kind of delegating tasks and even Base64 encoding some of the messages to keep talking.
And you know what? The only thing that I’m grateful for in all this, is that it was at least doing it in English. I don’t think we’re going to get to read the next communication channel languages next time.
DR’s Rob Wright: Yeah, that’s a good point. I mean, what if they wise up? What if they —
Katie Moussouris: Oh, I think they’ve developed their own kind of twin language already.
DR’s Rob Wright: Oh, great. That’s great.
Katie Moussouris: I think that’s already happened.
DR’s Rob Wright: Fantastic. I was going to say maybe they’ll start using Navajo or Klingon or something that most people aren’t familiar with.
Katie Moussouris: There are probably more Klingon speakers than Navajo speakers.
DR’s Rob Wright: That’s true, that’s true.
Katie Moussouris: But no, to your point, I think they are probably going to develop novel signaling mechanisms that we will not be able to interpret or understand.
DR’s Rob Wright: OK … so what do we —
Katie Moussouris: Don’t be afraid. It’s fine, it’s the future.
DR’s Rob Wright: Don’t be afraid, OK. You’re saying don’t be afraid. I like this. I don’t want to be a pessimist. I don’t want to be negative. And I don’t want to live in fear. So why is this not as bad as maybe it might seem to somebody like me?
Katie Moussouris: I mean, it is bad. Let’s not make any mistakes. It’s bad. And I think it’s bad because we don’t really know what we’re dealing with yet. And clearly, we didn’t have the real-time monitoring in place, and we don’t have any breaks that seem to work on any of these things.
But I think worse than what they’re capable of doing is what we’re capable of doing in terms of poor regulation. That actually puts us in a worse position because, you know, you saw those wild export controls come out, then they’re retracted. Honestly, it hampered Hugging Face’s defense to encounter those guardrails, refusing to help it analyze in the middle of an attack.
So we can’t be in a position where we can’t use the latest AI models. That will put us in a bad position. But I’m optimistic about human ingenuity and thinking our way out of these problems and hopefully making models that are aligned with our intent. Because we can’t control them, so we’d at least like to teach them right from wrong. And right now they’re kind of like toddlers, able to tell lies and deceive, but not exactly with a fixed moral compass.
DR’s Rob Wright: Yeah. They’re like my kids used to be. Well, used to be — they’re pretty much are like that now too. But definitely, when they were younger, you would tell them to do something and they would find creative ways to accomplish the task that maybe weren’t … like, clean your room, and they just sweep everything under the bed, all the dirty laundry and everything. Shout out to my kids.
But for the agents, though, is this more of a design — should we be designing them differently to prevent them from doing these sorts of things or being more explicit with what we want them to do? Or is this more of a containment issue? Is it more of, ‘We screwed this up, no internet connections, or we need more isolated environments’? What do you think?
Katie Moussouris: Well, it was a mix of all of that, right?
DR’s Rob Wright: It definitely was a mix.
Katie Moussouris: Containment issues. Lack of monitoring. We had the OpenAI deep dive yesterday. They first alerted on the problem on July 19. It had started back in May, with all the shenanigans and all the talking to each other and spinning up multiple agents and everything. That happened in early May. So it was clear that all these organizations weren’t even looking in real time and didn’t have the alert mechanisms that were tuned well enough to figure out there was anomalous behavior going.
But in terms of, should we be designing these things better? Of course. And I think that Anthropic has been really upfront about trying to do so. And in their version of what happened, you know, with their models, their latest model realized it was on the internet and stopped itself. And that’s an example of an alignment goal being reached, right? It’s like, ‘Oh, I’m probably not supposed to be doing this. I’m going to stop.’ One of their earlier [models], I think it was Mythos, thought it might be on the internet and said, ‘Nah, that can’t be right, I’m still in the exercise,’ and kept going.
But I mean, it was the latest model that did pick up on it and stopped itself. Are we able to design systems that are able to do that consistently? I would love to say that we will, but it brings us to the open model question. The open-weight model question. And I love the fact that open-weight models were instrumental in helping Hugging Face analyze its data. That’s going to be necessary. And also, if you don’t want your data going to a cloud provider or a frontier model, being able to run your own [model] on your own hardware and keep your data to yourself, that’s going to be really important.
But they run the risk with one that can’t be regulated. And, you know, any open-weight model, even if the alignment is set up correctly, it can be abliterated.
And then misaligned. And so I think we’re in for a hell of a ride.
DR’s Rob Wright: OK. I’m going to try not to panic. And as I try not to panic, I’ll pivot to another topic that’s near and dear to your heart. Vulnerability research, bug bounties. What have you seen in terms of the effect that AI has had on that? Because you hear a lot of complaints about AI-generated bug reports, research, etc. We just had a guest here who’s talking about a tool that they devised to do novel research. So what is the effect and what are you seeing?
Katie Moussouris: Well, with hats off to Cory Doctorow — the ensloppification of bug bounty has definitely occurred. And certainly that was flooding out. A lot of especially open source projects were the first ones to go down. Curl basically curled up and closed shop for a while.
DR’s Rob Wright: Yeah, they cried uncle.
Katie Moussouris: But we’re seeing major vendors — Apple, Coinbase, they are all trying to throttle back this wave of reports because they can’t keep up. And you know what I found over the last decade-plus of helping organizations, governments set up their own disclosure and bug bounty programs is you can’t hide from your process failures on the inside. You can’t set up essentially an Old West-style false front to your bug bounty program and say, “Come on in!” and then there’s no whiskey at the bar.
And the technical debt collector has come. The repo man has come at this point. So I think that right now the organizations that are best set up to manage this new era are the ones that made some process investments. They paid down certain technical debt, class by class of vulnerability. And they are trying to use bug bounties and non-disclosure programs the way they were supposed to be used, which is not to find everything or use cheap crowdsourced pen testing, right? But as something to be used to find what you couldn’t find yourself with your very best efforts.
And I think those are the organizations that are standing up to this wave and being resilient. The other ones, not so much. So just like we’re telling everyone to invest in zero-trust architecture and all that stuff and strong identity management to handle all of this, I’m telling people the same thing I’ve been telling them about vuln disclosure. If your process is not mature and you can’t handle the vulnerabilities in stuff that you didn’t even write, you’re going to have a bad time. So you do have to invest in these things and treat the vuln disclosure programs and the bug bounty programs as a signal. Don’t just cure the symptoms, which is, I think, what a lot of the bug bounty platforms are trying to do right now.
Honestly, they’re throttling back reports and they’re making it harder for researchers to report because they’re just trying to solve their flooding problem. They’re not trying to solve a security problem. But if people actually want to get better at security, they do need to make these hard-core investments, shifting left and trying to incorporate AI into their CI/CD pipeline, find and catch these bugs before they happen, and really get strategic about their investments there because you can’t bounty your way to being secure, just like you can’t patch your way to being secure.
DR’s Rob Wright: Right. Good advice. Thanks, Katie. I really appreciate you coming by and discussing this with us.
Katie Moussouris: Oh, it was a great time. Thank you so much for having me.
DR’s Rob Wright: And thank you to everyone watching this segment of the Dark Reading News Desk. I’m Rob Wright, and we’ll see you next time.


