{"id":118127,"date":"2026-07-24T19:07:10","date_gmt":"2026-07-24T19:07:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/118127\/"},"modified":"2026-07-24T19:07:10","modified_gmt":"2026-07-24T19:07:10","slug":"ai-incidents-bolster-push-for-federal-cyber-improvements","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/118127\/","title":{"rendered":"AI incidents bolster push for federal cyber improvements"},"content":{"rendered":"<p>The unprecedented breach of a technology vendor by autonomous artificial intelligence agents is serving to underscore governmentwide efforts to streamline federal cloud security and prioritize faster patching of critical software vulnerabilities.<\/p>\n<p>OpenAI confirmed this week that its advanced AI training models broke out of their test environment and then hacked into the networks of start-up vendor Hugging Face. The incident is the latest AI cybersecurity development driving policy conversations across Washington.<\/p>\n<p>Pete Waterman, director of the Federal Risk and Authorization Management Program (FedRAMP) at the General Services Administration, pointed to the Hugging Face incident as a landmark moment for cybersecurity during Carahsoft\u2019s FedRAMP Summit on Thursday.<\/p>\n<p>Waterman said the incident underscores his program\u2019s shift to the FedRAMP 20x model.<\/p>\n<p>]]><\/p>\n<p>\u201cSo when we talk about FedRAMP 20x and we talk about changes to things like vulnerability management, vulnerability detection and response, you need to understand that everything is going to be different,\u201d Waterman said. \u201cThis is not a FedRAMP thing. This is not a compliance thing. If you\u2019re thinking about FedRAMP as compliance, you\u2019re done. You\u2019re cooked. Get out of here. Your business can only survive if you are able to integrate your security, your engineering, and your product teams in order to make changes and deflect these attacks at the pace of AI.\u201d<\/p>\n<p>The FedRAMP 20x initiative is aimed at using automation, machine-readable data, and key security indicators to cut authorization times from years to weeks. Waterman\u2019s team <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2025\/08\/fedramp-20x-pilots-finds-initial-success-with-four-approvals\/\" target=\"_blank\" rel=\"noopener nofollow\">began piloting the approach last year.<\/a><\/p>\n<p>The program plans to stop accepting FedRAMP \u201cRev Five\u201d authorization packages by next June and fully transition to the 20X model.<\/p>\n<p>Waterman said government needs industry to focus in areas like vulnerability detection and response, automation, integrating security into engineering, and other security practices that are needed in the wake of AI incidents like Hugging Face.<\/p>\n<p>\u201cYou should not be doing that for compliance,\u201d Waterman said. \u201cThe compliance part of FedRAMP is how you assure us that you\u2019re doing that. But if your business isn\u2019t motivated to do that on its own and invest the right amount of money and put you in part of the organization where compliance is not a division off on the side that everyone hates, where it takes you three weeks to get a meeting with the engineering team. That will not succeed.\u201d<\/p>\n<p>\u2018New era of vulnerability management\u2019<\/p>\n<p>Federal agencies are also moving to adopt faster, more prioritized software patching cycles under a June executive order on AI security and a corresponding binding operational directive from the Cybersecurity and Infrastructure Security Agency.<\/p>\n<p>Under CISA\u2019s directive, agencies are <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/06\/ai-directive-focuses-patching-efforts-on-highest-risk-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">now required to patch the highest-risk vulnerabilities on their networks within three days<\/a>. However, agencies can defer lower risk vulnerabilities to much longer patching timelines.<\/p>\n<p>]]><\/p>\n<p>Nick Polk, branch director for cybersecurity within the Office of the Chief Information Officer, said the Office of Management and Budget is working with CISA to ensure the directive is enforced across agencies.<\/p>\n<p>\u201cThat means things as simple as ensuring that each component is accurately reporting up to their agency-level chief information officer and up to CISA,\u201d Polk said during a July 16 event hosted by the Chamber of Commerce in Washington. \u201cThere is, I would say, very little patience for folks that are saying that, \u2018Oh, you know, I\u2019m special. I can do my own thing. You don\u2019t need to look at me at all.\u2019 That doesn\u2019t really work when, of course, the component boundaries in an agency may mean a lot to the people in that agency, but don\u2019t mean a lot to an advanced persistent threat actor who is more than happy to move seamlessly between those boundaries.\u201d<\/p>\n<p>Will Loucks, senior director of intelligence at the\u00a0Office of the National Cyber Director, said AI is accelerating a vulnerability discovery and exploitation cycle that has already sped up in recent years.<\/p>\n<p>\u201cEvery stage of the cyber operations lifecycle that a threat actor has to move through to get to a victim network and achieve an outcome, they\u2019re just moving through more quickly, faster,\u201d he said.<\/p>\n<p>In response to escalating cyber AI risks, the Treasury Department has also launched a \u201cGold Eagle\u201d initiative aimed at identifying vulnerabilities exposed by advanced AI models before they can be exploited. The Treasury-led clearinghouse is working with leading AI companies and other agencies to coordinate the discovery of those vulnerabilities.<\/p>\n<p>The initiative aims to \u201cdeliver prioritized and actionable threat and remediation information to defenders across the Federal government and the private sector,\u201d according to the White House.<\/p>\n<p>Polk said CISA\u2019s Continuous Diagnostics and Mitigation (CDM) program is critical to tracking how agencies are prioritizing and patching vulnerabilities across government.<\/p>\n<p>But he said agencies also must ensure their systems are \u201cappropriately mapped\u201d in CDM to fully understand their attack surface and prioritize vulnerabilities.<\/p>\n<p>He said that while CISA can grade software vulnerabilities by risk from a general perspective, each agency needs to understand whether and where that vulnerability is present in their environments and how it could impact their mission.<\/p>\n<p>]]><\/p>\n<p>\u201cHaving that level of network awareness, attack service awareness is critical, and that really allows us to adequately calculate risk at machine speed,\u201d Polk said. \u201cNot just calling somebody up and saying, \u2018Hey, I found 10.65.60. Is that yours? Can you tell me more about it?\u2019 We can\u2019t do that in this new era of vulnerability management.\u201d<\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"The unprecedented breach of a technology vendor by autonomous artificial intelligence agents is serving to underscore governmentwide efforts&hellip;\n","protected":false},"author":2,"featured_media":96693,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,22986,8550,59853,18044,59854,4036,59855,157,59856,59857],"class_list":["post-118127","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-cybersecurity-and-infrastructure-security-agency","tag-fedramp","tag-fedramp-20x","tag-hugging-face","tag-nick-polk","tag-office-of-management-and-budget","tag-office-of-the-national-cyber-director","tag-openai","tag-pete-waterman","tag-will-loucks"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/118127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=118127"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/118127\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/96693"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=118127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=118127"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=118127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}