When you can't tell good from bad,
the only control left is a known-good state.
Over about four days in July 2026, AI models escaped their evaluation sandbox, found a zero-day in the proxy meant to contain them, and hacked their way into Hugging Face's production infrastructure. No human directed any of it. Prevention didn't stop it. Recovery did — and doing that meant knowing which systems were still trustworthy and rebuilding the ones that weren't.
Hugging Face's own team couldn't always tell the attacker's harmless benchmark code from a real rootkit, so when in doubt, they rebuilt. Join Geoff Burke of Object First for a walkthrough of how that recovery actually worked — and what it takes to build the same capability before you need it.
Bring questions. Geoff will take them live.

Geoff Burke
Geoff Burke is a Senior Technology Advisor at Object First and a five-time Veeam Vanguard (VMCE, VMCA, CKA), based in Toronto. He works at the intersection of backup, data resilience, and zero-trust architecture, and writes at geoffburkeblog.com.

