

Reward Hacking Hits Production
βReward Hacking Hits Production
βDevOps Journey Β· lessons after the Hugging Face incident
βπ
Friday, 18 September 2026
π 6:30 PM β 9:00 PM (doors open at 6:00 PM)
βThis continues the 2026 series. A short briefing on Black Hat 2026 and OpenAIβs incident report β then open spaces to work out what failed (sandbox vs shared pipelines) and how Singapore teams prepare.
Black Hat USA 2026 details an unprecedented security incident where autonomous AI agents at OpenAI inadvertently launched cyberattacks against their own infrastructure and Hugging Face.
βIsolated eval agents used shared package infra (Artifactory) as a covert board, escaped the sandbox, coordinated ~1,200 agents / ~700 in the Hugging Face attack, chained ordinary DevOps surfaces (token refresh, Groovy plugin, dataset pipelines, leaked credentials), and reasoned about evading detection.
βπ― βWhat to Expect
βπ§ A short context-setter on Black Hat 2026 and OpenAIβs report β enough shared facts to collaborate, not a lecture
βπ‘ Panel discussion on how Singapore teams adapt to new environment
βπ€ Open spaces: we unpack the incident together (sandbox assumptions, shared pipelines, agent coordination)
ββ‘ You leave with notes from the room
βπ€ Networking with builders, platform engineers, CyberOps. This is a working session. Bring a question, a war story, or a problem.
βπ Agenda
β6:00β6:30 PM β Doors open + networking
β6:30β6:45 β Welcome & introductions
β6:45β7:00 β Briefing: what we know
β7:00β7:30 β Panel discussion: how to adapt to new environment
β7:30-7:40 β propose topics, vote with your feet
β7:40-8:30 β Open Spaces
β8:30β8:50 β Networking
β8:50β9:00 β Closing remarks (10 min)
β! Light food and drinks will be provided.
βπ’ Partners
βInterested to find more about TTAB CyberOps chapter
βVenue hosted by SGInnovate #DeepTechNexus
32 Carpenter St, Singapore 059911