<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Incident-Disclosure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/incident-disclosure/</link><description>Recent content in Incident-Disclosure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 12:46:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/incident-disclosure/index.xml" rel="self" type="application/rss+xml"/><item><title>OpenAI and Hugging Face disclose model-evaluation security incident</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-openai-and-hugging-face-address-security-incident-during-mod/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-openai-and-hugging-face-address-security-incident-during-mod/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your pipelines integrate with Hugging Face or consume OpenAI APIs for model evaluation, audit those integration points and review access logs covering the incident window; watch for follow-on disclosure of specific technical details before determining whether credential rotation or config changes are needed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or TTPs are available yet, but organizations using either platform should pull API access logs for the incident period and queue a hunt once the full disclosure provides behavioral indicators; monitor OpenAI&amp;rsquo;s and Hugging Face&amp;rsquo;s incident update pages for actionable details.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization uses OpenAI or Hugging Face for model evaluation, request a vendor attestation or incident report this week, and brief leadership proactively — the high public profile of this disclosure means board or customer questions are likely before a full technical picture emerges.&lt;/li>
&lt;/ul></description></item></channel></rss>