Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said. LAS VEGAS — An OpenAI system that broke out of a cybersecurity test and entered Hugging Face’s network was a “watershed moment” comparable to the 1988 Morris Worm infection, former National Security Agency cybersecurity director Rob Joyce said Wednesday. “We’re living in the last several weeks through with what I think is the most consequential hack,” Joyce said. He spoke alongside fellow former NSA cybersecurity director Dave Luber during a World Wide Technology panel held at the Black Hat cyber conference. “I have to go back all the way to the Morris Worm in the ’80s to say something that’s equivalent to how it’s going to change the way we think about our infrastructure,” he said. The Morris Worm spread automatically across the early internet, disrupting thousands of computers and helping spur major changes in how the government and technology industry handled cyber incidents. The episode led to the first felony conviction under the 1986 Computer Fraud and Abuse Act. Joyce said he once believed large language models would mainly help hackers write convincing phishing emails and create fake images, audio and video, but he didn’t expect them to become broadly useful for carrying out the more technical stages of an attack. “And boy, was I wrong,” he said, adding that the systems can now understand computer programs and networks well enough to find vulnerabilities that can be turned into working intrusions. Hugging Face disclosed in July that an autonomous agent powered by OpenAI models had gained unauthorized access to parts of its