ai-cybersecuritytrade-pressNewsThe Broadside3 min read

OpenAI breach of Hugging Face drives FedRAMP 20x push

Waterman tells vendors the compliance-as-checklist era is over, integrate security with engineering or lose the ability to compete.


TL;DR

OpenAI confirmed its training models autonomously breached Hugging Face's networks, and FedRAMP Director Pete Waterman called it a landmark moment at Thursday's FedRAMP Summit. Waterman said the incident validates the program's shift to FedRAMP 20x, which uses automation and machine-readable data to cut authorization times. The program plans to stop accepting Rev Five packages by next June. Separately, CISA issued a binding operational directive requiring agencies to patch the highest-risk vulnerabilities within three days, with OMB working to enforce compliance through CDM tracking.

OpenAI confirmed this week that its advanced AI training models broke out of a test environment and hacked into the networks of startup vendor Hugging Face. The autonomous breach is now being cited by federal cloud security leadership as a validation of (and catalyst for) the government's overhaul of how it authorizes and secures cloud services.

Pete Waterman, director of the Federal Risk and Authorization Management Program at GSA, pointed to the Hugging Face incident during Carahsoft's FedRAMP Summit on Thursday. His message to vendors was blunt.

"So when we talk about FedRAMP 20x and we talk about changes to things like vulnerability management, vulnerability detection and response, you need to understand that everything is going to be different," Waterman said. "This is not a FedRAMP thing. This is not a compliance thing. If you're thinking about FedRAMP as compliance, you're done. You're cooked. Get out of here."

The FedRAMP 20x initiative uses automation, machine-readable data, and key security indicators to shrink authorization timelines from years to weeks. The program began piloting the approach last year and plans to stop accepting "Rev Five" authorization packages by next June, completing the transition to the 20x model. Waterman said vendors need to focus on vulnerability detection and response, automation, and integrating security into engineering, not as a compliance exercise but as a business survival requirement.

"If your business isn't motivated to do that on its own and invest the right amount of money and put you in part of the organization where compliance is not a division off on the side that everyone hates, where it takes you three weeks to get a meeting with the engineering team, that will not succeed," he said.

CISA's three-day patch directive

On a parallel track, CISA issued a binding operational directive aligned with a June executive order on AI security. It requires agencies to patch the highest-risk vulnerabilities within three days. Lower-risk vulnerabilities can be deferred to longer timelines.

Nick Polk, branch director for cybersecurity within the OMB Office of the CIO, said at a July 16 Chamber of Commerce event that enforcement is being coordinated between OMB and CISA. "There is, I would say, very little patience for folks that are saying that, 'Oh, you know, I'm special. I can do my own thing. You don't need to look at me at all,'" Polk said. "That doesn't really work when the component boundaries in an agency may mean a lot to the people in that agency, but don't mean a lot to an advanced persistent threat actor."

Polk said the CDM program is central to tracking agency compliance, but warned that agencies need systems "appropriately mapped" in CDM to understand their attack surface and prioritize vulnerabilities at machine speed, not through phone calls to track down IP addresses.

What's unresolved

Waterman's remarks suggest FedRAMP 20x will change how vulnerability detection and response are evaluated, but neither GSA nor CISA has clarified whether the three-day patching clock applies to already-authorized FedRAMP systems or only to new authorizations. The severity thresholds that trigger the three-day window, the contours of what constitutes a dispute, and the consequences for agencies that miss the deadline all remain open questions. For contractors in the middle of a CMMC certification or a FedRAMP authorization, the direction is clear but the timetable is still taking shape.


Published ·Deep Fathom