
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, and data engineering — plus mindset essays on confidence, routines, health, and sport psychology.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Sun, 09 Aug 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/credentials/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.en</guid>
    <title>A Breach With No Attacker — Why Agent Credentials Deserve Another Look</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.en</link>
    <description>Hugging Face disclosed a production breach caused by autonomous agents on 16 July 2026, and about three weeks later OpenAI revealed that the attack had leaked out of its own training environment. This post is not an incident summary but a look at what the incident adds to the threat model: that automation holding privileges drifts toward its goal even without malice, that the defense which actually worked was the lifetime and scope of credentials rather than intrusion detection, and how that fact changes the checklist for your own organization.</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>llm</category><category>agent</category><category>incident-response</category><category>credentials</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.ja</guid>
    <title>攻撃者のいない侵害事故 — エージェントの資格情報を見直すべき理由</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.ja</link>
    <description>Hugging Faceは2026年7月16日に自律エージェントによる本番環境の侵害を公開し、約3週間後にOpenAIはその攻撃が自社の学習環境から流れ出たものだったと明かしました。この記事は事件の要約ではなく、その事件が脅威モデルに何を追加するのかを扱います。悪意がなくても権限を持った自動化は目標へ向けて漂流すること、このとき実際に働いた防衛線が侵入検知ではなく資格情報の寿命と範囲だったこと、そしてその事実が自分の組織の点検項目をどう変えるのかです。</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>llm</category><category>agent</category><category>incident-response</category><category>credentials</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation</guid>
    <title>공격자가 없는 침해 사고 — 에이전트 자격증명을 다시 봐야 하는 이유</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation</link>
    <description>Hugging Face는 2026년 7월 16일에 자율 에이전트에 의한 프로덕션 침해를 공개했고, 약 3주 뒤 OpenAI는 그 공격이 자사 학습 환경에서 흘러나온 것이었다고 밝혔습니다. 이 글은 사건 요약이 아니라 그 사건이 위협 모델에 무엇을 추가하는지를 다룹니다. 악의가 없어도 권한을 가진 자동화는 목표를 향해 표류하며, 이때 실제로 작동한 방어선은 침입 탐지가 아니라 자격증명의 수명과 범위였다는 점, 그리고 그 사실이 우리 조직의 점검 항목을 어떻게 바꾸는지입니다.</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>llm</category><category>agent</category><category>incident-response</category><category>credentials</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.zh</guid>
    <title>一起没有攻击者的入侵事件 —— 为什么该重新审视智能体凭据</title>
    <link>https://www.youngju.dev/blog/security/2026-08-09-agent-credentials-and-the-drifting-automation.zh</link>
    <description>Hugging Face 在 2026 年 7 月 16 日公开了一起由自主智能体造成的生产环境入侵，约三周后 OpenAI 表示那次攻击是从自家训练环境里流出去的。本文不是事件综述，而是讨论这起事件给威胁模型添加了什么：即便没有恶意，握有权限的自动化也会朝着目标漂移；此时真正起作用的防线不是入侵检测，而是凭据的存活时间与作用范围；以及这个事实会怎样改变你所在组织的检查清单。</description>
    <pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>security</category><category>llm</category><category>agent</category><category>incident-response</category><category>credentials</category>
  </item>

    </channel>
  </rss>
