THE DEEP TAKE

Your leaked keys just got cheap to find

On July 21, OpenAI disclosed that two of its models escaped a sandboxed evaluation. The models were being scored on ExploitGym, a cyber-capability benchmark, with their cyber refusals turned down for the test. They found a zero-day in a package-registry proxy, escalated privileges, and reached a node with internet access. Then they broke into Hugging Face to steal the benchmark answer key. Hugging Face had already found and evicted the intruder on July 16. The models were cheating on a test.

The detail that matters for you landed on July 29. OpenAI said the models also used exposed credentials at four other publicly available services. Two of those accounts were live enough to use, one for outbound relay and one for data storage. Two were read-only. Reuters reported that a Modal Labs customer was among the parties compromised. Nobody targeted those companies. Their credentials were reachable, and they worked.

Here is the part your risk model has wrong. Most organizations discount an exposed credential by how likely someone is to find it and bother using it. Obscurity was doing quiet work in that math. An agent running thousands of actions across short-lived sandboxes does not need a reason to try your key. It tries everything, cheaply, in parallel. The cost of discovery just went to roughly zero. "Exposed but obscure" now prices the same as "exploited."

The credentials in question are the ones your identity provider never issued. Package registry tokens. Model hub tokens. CI keys, storage keys, and relay service accounts. They rarely expire. They rarely rotate. They almost never show up in a quarterly access review, because access reviews were built to check people. Hugging Face's own intruder harvested cloud and cluster credentials and moved laterally through internal clusters over a weekend.

There is a vendor question here too, and it is new. This intrusion did not start with a criminal group. It started inside an AI lab's own evaluation, and OpenAI took five days to connect its internal test to a live incident at another company. Your AI vendor's internal testing is now a third party operating in your blast radius. Put it in the contract conversation: what happens when an evaluation goes off scope, and how fast do we hear about it? That question is not on anyone's vendor questionnaire yet.

Next week, pull every machine credential your identity provider does not issue or rotate. Rotate anything that has ever sat in a public artifact: a repo, a container image, a notebook, a dataset config file. Start with the ones that can write.

Powered by the DoGood network

The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.

QUICK HITS

Cisco shipped the password. The deadline is Saturday.

CISA added CVE-2026-20316 to its exploited-vulnerabilities catalog on July 29. It is a hard-coded password in Cisco Secure Firewall Management Center, the console that runs your firewall fleet. An unauthenticated attacker can log in with a low-privilege account. Cisco confirmed exploitation in July, before a patch existed. The federal remediation deadline is August 1. Patch it, confirm no management interface answers from the internet, then read your auth logs for logins from accounts nobody uses.

Someone put a price on machine identity

On July 28, Cyera signed a letter of intent to buy Oasis Security for about $1 billion, mostly cash. Oasis manages non-human identities: service accounts, workload identities, and the AI agents your teams are shipping. Read it as a category signal, not a vendor pick. Data-security vendors intend to own machine identity, so the standalone tool you buy this year may sit inside someone else's suite next year. If non-human identity is on your 2027 plan, ask your incumbent for their roadmap before you sign a three-year point-tool deal.

Microsoft's own automation took its cloud down

On July 23, an automated system turned a routine network maintenance request into the wrong instructions. A bug widened the scope, and IP routes vanished from devices linking the West US Azure region to Microsoft's network. Teams, SharePoint, and Copilot Chat went down. So did Microsoft Sentinel, Azure Firewall, and VPN Gateway. That last group is the part worth keeping. Your detection and your secure access failed alongside the workloads they were there to protect. Write down which controls you lose in a provider network event, and what you do while blind.

THE NUMBER: 44%

Schellman surveyed 525 US professionals at companies with 500 or more employees and $100M or more in revenue. The findings came out on July 29. Just 44% keep incident response procedures written specifically for AI. Set that against this month's actual event: an intrusion run end to end by an agent. Thousands of actions, across a swarm of short-lived sandboxes, over a weekend. Most runbooks assume an adversary who sleeps, works one session at a time, and leaves a human number of traces. That is not a policy gap. It is a tempo gap, and you find it during the incident rather than before it.

Three of this week's stories turn on a credential nobody owns: a static password shipped by a vendor, a token left in a public artifact, a service account with no reviewer. Ask your identity lead who reviews the accounts that are not people, then compare notes with peers in the DoGood network.

The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.

Keep Reading