🎯 SUCCESS 🧠 BRAIN 💸 MONEY 🧭 SPACES 🌍 TRAVEL 🎙️ PODCASTS 📺 VIDEOS 🎥 CRIME & MOVIES
  • Skip to main content

Mad Mad News

CURATED FOR CLARITY

Curated for Clarity

BUSINESS

SK Hynix denies Intel Ohio fab deal, but the market didn’t care

July 22, 2026 MMN Editor Filed Under: SUCCESS, The Street

A report out of South Korea on Tuesday, July 21, claimed SK Hynix was in talks to buy Intel’s unfinished Ohio semiconductor campus, according to Stocktwits.The claim traced back to Korea JoongAng Daily and described a deal that would give SK Hynix front-end memory production in the United States, years ahead of its own internal timeline.Now SK Hynix is dismissing it. In a filing with the Korea Exchange, the company said it “has not pursued or decided to acquire Intel’s Ohio site and Fab as reported in the article,” TipRanks reported.A company spokesperson went further, telling Benzinga simply that SK Hynix has no plans for an acquisition.Intel did not confirm or deny the talks directly. An Intel spokesperson told Benzinga the company does not comment on deal speculation but remains committed to Ohio and to speeding up the site’s readiness.The SK Hynix denial didn’t erase Intel’s rallyIntel (INTC) closed July 21 at $105.45, up 8.64% on the day.That gain held even as the acquisition story it was riding fell apart hours later. This matters because markets usually give back speculative pops once the trigger disappears.SK Hynix followed a similar pattern in Seoul. Shares opened up more than 9% on the original report, then trimmed to a 6.7% gain once the denial filing landed, TradingKey confirmed.A stock that gives back a third of its gain on a denial but still finishes up nearly 7% is not a stock that stopped believing the story.The one exception was SK Hynix’s own US-listed shares (SKHY), which slipped about 1.4% in the overnight session after the denial.That gap between how Seoul traded the news and how New York traded it says something about who was pricing in a real deal and who was just reacting to a headline.

SK Hynix denied plans to acquire Intel’s Ohio chip campus, but Intel and SK Hynix shares held onto sharp gains anyway.Bloomberg / Getty Images

Intel’s foundry losses made the rumor easy to believeThe reason the story had legs is Intel’s balance sheet. Intel Foundry has been bleeding cash, posting a $7 billion operating loss in 2023 and another $2.4 billion in the first quarter, according to TipRanks.A struggling foundry business sitting on a mostly idle 1,000 acre campus is exactly the kind of asset investors expect a cash-strapped company to consider selling.Related: SK Hynix makes jaw-dropping gains in wild Nasdaq trading debutIntel has pushed the Ohio site’s production timeline back to 2030 or 2031, citing challenging market conditions and the need to strictly manage its capital, Construction Dive reported.A campus that will not run chips for another four or five years is easier to imagine changing hands than one already generating revenue.SK Hynix doesn’t need this deal to keep growing in the U.S.SK Hynix is already building a $3.87 billion HBM packaging plant in Indiana, and the market knows it has an appetite for more.SK Group Chairman Chey Tae-won recently confirmed the company is aggressively scouting additional U.S. and Korean sites for future wafer fabs, as long as the right power, water, and workforce conditions are met, Bloomberg indicated.More SK Hynix:Jim Cramer’s cryptic comments on key AI supplier turn headsMajor AI chip stock plunges after blockbuster $26.5 billion Nasdaq debutSK Hynix is testing the limits of Wall Street’s ETF boomThe appetite for U.S. capacity is genuine. This particular target just was not it.Moor Insights and Strategy CEO Patrick Moorhead called the Intel talks unlikely, noting that Ohio remains central to Intel’s plan to win outside foundry customers, StockTwits reported.Selling the campus SK Hynix supposedly wanted would undercut the exact turnaround story Intel is trying to sell investors ahead of its Thursday, July 23, earnings report.A denial is not the same as a closed doorWhat happened this week is less about one campus in New Albany and more about how thin the line has gotten between memory chip supply and desperation.AI demand has made HBM capacity scarce enough that investors will bid up two stocks on a deal neither company confirms, then barely blink when it gets denied.Intel reports earnings on Thursday, and direct questions about the Ohio site’s future will be asked.Until then, the market has already told investors what it thinks a deal between these two companies would be worth, whether or not one ever gets signed.Related: SK Hynix is testing the limits of Wall Street’s ETF boom

7 Power Moves to Beat Mediocrity

July 22, 2026 MMN Editor Filed Under: BUSINESS

How to strengthen your mind, money and momentum by studying the moves reshaping technology, media, business, health and culture.

Mediocrity rarely arrives with an announcement. It settles in quietly.

It looks like postponing one important decision, accepting another draining routine, consuming information without doing anything with it, or waiting for confidence before taking action.

The world’s biggest organizations, creators and industries do not move forward by waiting for perfect conditions. They look for leverage, protect their strongest assets and act before everyone else understands the opportunity.

We can do the same in our own lives.

Power Move No. 1

Take Control of Your Attention

Attention has become one of the world’s most valuable resources. Every platform, headline, advertisement and notification is competing for yours.

The first power move is deciding what deserves it. Choose a limited number of reliable information sources. Review the news at intentional times instead of allowing it to interrupt your entire day.

Being informed should make you more capable—not permanently agitated.
Power Move No. 2

Stop Confusing Motion With Momentum

A busy day can still produce nothing meaningful. Motion fills time. Momentum changes your position.

Momentum comes from completing the proposal, publishing the article, contacting the client, making the appointment or removing the expense that keeps draining your account.

Before today ends, complete one task that makes tomorrow easier.

Power Move No. 3

Make One Intelligent Money Move

You do not have to solve your entire financial future tonight. Make one useful move:

  • Cancel an expense you no longer value.
  • Move a small amount into savings.
  • Review one recurring charge.
  • Develop one additional income opportunity.
  • Learn one financial concept you have avoided.
  • Contact someone who could open a business door.

Major financial improvement is often the accumulated result of modest decisions made consistently.

Power Move No. 4

Use Technology as Leverage—Not as a Substitute for Judgment

Artificial intelligence can accelerate research, organization, writing, analysis and problem-solving. It can also produce polished nonsense.

The advantage does not belong merely to the person using AI. It belongs to the person who combines AI with experience, skepticism, taste, responsibility and human judgment.

Let the machine increase your reach. Do not let it replace your judgment.
Power Move No. 5

Protect Your Energy Like a Strategic Asset

Organizations protect capital, intellectual property and infrastructure. Individuals should protect their energy with the same seriousness.

Notice what repeatedly exhausts you without producing growth. Reduce unnecessary conflict. Create boundaries around work that matters. Protect time for sleep, movement, recovery and clear thinking.

You cannot carry a larger opportunity with a permanently depleted mind and body.

Power Move No. 6

Study the Power Moves Happening Across Sectors

Innovation rarely remains inside one industry. Technology changes health care. Media changes politics. Transportation changes real estate. Space exploration produces advances in communications, materials and engineering.

Do not study only your own field. Look across business, science, culture, entertainment, money and technology.

What is changing in another sector that could eventually change my work, income or choices?

The opportunity often appears before the job title does.

Power Move No. 7

Build Toward a Larger Identity

The strongest move is deciding that your current routine is not the full measure of your future.

You may be building a company, recovering from hardship, creating art, improving your health or starting again later in life. The exact direction matters less than refusing to let today’s circumstances define the boundary of tomorrow.

You do not beat mediocrity by feeling superior to other people.

You beat it by becoming more intentional than you were yesterday.

Your Move Tonight

Choose one action from this article and complete it before you go to sleep.

Not seven. One.

Tomorrow, choose another.

That is how a larger life begins—not with noise, but with movement.

Live Above the Madness.

Share on Facebook Explore More MMN

Senator Lummis: Ethics, other provisions in crypto Clarity Act to be further discussed

July 22, 2026 MMN Editor Filed Under: Coindesk, SUCCESS

Senator Cynthia Lummis, one of the lead negotiators on the bill, told CoinDesk she was “pleased” that the updated bill was ready for release.

Landlords sound alarm as rental fraud costs renters big

July 22, 2026 MMN Editor Filed Under: SUCCESS, The Street

Every lease starts as a bet between strangers.The landlord bets that the person on the other side of the application is who they claim to be and earns what they claim to earn. The renter bets that the apartment in the photos exists and that whoever is collecting the deposit actually owns the place.For most of the last century, that bet got settled face to face. You met the landlord, you walked the unit, and somebody looked you in the eye and made a judgment call.Then the process moved online, and the eye contact went away. Applications became uploads. Tours became video walkthroughs.Approvals became a decision made by someone three time zones away who has never stood in the building.Renters have been trained to worry about one half of that arrangement. The copied listing. The deal that is too good. The wire transfer that vanishes.Far fewer are watching the other half, where a bigger and costlier fraud fight is under way, and where honest applicants are quietly picking up the tab.What renters already know about rental listing scamsThe visible version of this problem is bad enough on its own. Since 2020, people have filed nearly 65,000 rental scam reports totaling about $65 million in losses, according to the Federal Trade Commission.The playbook rarely changes. Scammers copy a real listing, swap in their own contact details, repost it elsewhere and push the renter to send money before anyone walks the property.More Real Estate:Kevin O’Leary spots a real estate play hiding in plain sightThe U.S. housing affordability crisis just got a major responseWhy mortgage rates are spiking again and what to doFacebook was the most reported starting point, accounting for roughly half of reports in the 12 months through June 2025, with Craigslist next at 16%. The median reported loss was $1,000.Young renters bear the brunt of it. People ages 18 to 29 were three times more likely than other adults to report losing money this way.The defense is familiar. Search the address, check whether the same unit appears elsewhere at a different price, and never hand over a Social Security number before you have agreed to rent, guidance from Zillow explains.That is the fraud renters can see coming. It is not the one reshaping what they pay.

Rental scams cost renters $65 million, while AI application fraud raises deposits for honest applicants.ABRAHAM GONZALEZ FERNANDEZ / Getty Images

How AI rent fraud slips past landlord screeningLos Angeles landlord Michael Renkow approved a tenant in September 2025 for two units renting at $5,300 a month each. The bank statements, employment records, and ID all cleared.Two days later, his bank flagged the cashier’s checks as fraudulent, and someone was already living in the apartment and refusing to leave, reported Bisnow. The seven-month eviction that followed cost $90,000.What changed is the price of a convincing lie. Forging a pay stub used to take skill or a trip to the dark web. Generative tools cut that down to a prompt and a small fee.Related: Real estate giant updates mortgage rate, home price predictionsMRI Real Estate Software bought 200 artificial intelligence-generated fake IDs, some for as little as $5, and ran them against the optical card readers most leasing offices depend on. The readers flagged 26% of them.Roughly three in four walked through the front door.Documents are the entry level. Some fraudsters now register real limited liability companies and issue real-looking pay stubs from those businesses to people who do not exist, Findigs CEO Steve Carroll explained in an interview with TheStreet.That is a synthetic identity, and it beats document review by design. The document is not forged. The company is.The identity layer is moving the same way. Deepfakes now account for one in five biometric fraud attempts, and deepfaked selfies rose 58% in 2025, according to Entrust.Why honest renters absorb the cost of rental fraudHere is the part nobody prints in a leasing brochure. Fraud losses do not stay with the landlord. They get priced into the next lease.When I lined the industry surveys up against the federal data, the gap was the story. Renters report losses one at a time in four-figure increments. Operators absorb theirs in seven figures and rebuild their screening rules around it.The numbers behind that gap:Nearly all rental housing providers surveyed, 93.3%, reported experiencing fraud in the prior 12 months, according to the National Multifamily Housing Council.The average respondent wrote off close to $4.2 million in bad debt over that period, with about a quarter of it tied to nonpayment on fraudulent applications, the same NMHC survey confirmed.On average, 23.8% of eviction filings traced back to fraudulent applications and the missed rent that followed, NMHC found.More than 70% of property managers said most fraud surfaces only after move-in, according to Snappt.Real estate fraud drew 12,368 complaints and $275.1 million in reported losses last year, the FBI’s Internet Crime Complaint Center noted.Each application fraud case runs about $15,000 to clean up, said Kevin Donnelly of the Real Estate Technology and Transformation Center, who told Bisnow the cost “ultimately gets borne by the community.”In a renter’s terms, that is a larger deposit, a higher income multiple, a co-signer requirement that did not exist three years ago and an approval that takes days instead of hours.Not everyone accepts the framing. Much of the data comes from the industry itself, and expanded screening carries its own fees and its own risk of shutting out qualified renters, argued National Consumer Law Center senior attorney Ariel Nelson in the same report.That tension is why rental screening is becoming a policy fight rather than a technology one. What a clean rental application looks like nowThe uncomfortable finding in my analysis is that the honest applicant now competes against a fraudster with better paperwork.A fabricated pay stub can be built to hit the income multiple exactly. A real one from a small employer or a gig platform often looks messier than the fake.So the advantage has shifted toward verifiability: documents a screener can trace to a source, payroll data that can be confirmed directly, an identity that survives more than an optical glance.”A renter can’t out-negotiate a manual review process that takes days and depends on whoever happens to be looking at the file that week,” said Carroll in the interview. “What they can ask for is a process that decides the same way every time, fast, on evidence instead of a gut check.”Findigs says it renders automatic decisions across a network of more than 400,000 units, with fraud signals shared across that network.Whether automation helps renters depends on what it is tuned to do. Pointed at risk, it becomes one more reason to say no. Pointed at evidence, it is the closest thing a renter has to a fair hearing.The arms race will not slow down, because both sides are buying the same tools. What renters can control is how fast they can prove they are real, and that is worth more at the leasing office right now than another month of deposit money.Related: When to buy a home instead of continuing to rent, according to Scott Galloway

The oil spike everyone feared never showed up

July 22, 2026 MMN Editor Filed Under: SUCCESS, The Street

Forecasting is mostly a way of buying peace of mind. You want a number for the worst case so you can decide how frightened to be, and once you have that number, you quietly stop thinking and start bracing for it.That instinct is not irrational. It is how you decide whether to refinance, whether to take the job across town, whether the August road trip is still on.Then late February arrived, and the worst case got a number.When the United States and Israel struck Iran on Feb. 28, Tehran shut the Strait of Hormuz, the narrow channel that carries roughly a fifth of the world’s oil and refined products. The forecasts that followed were not subtle. Trading desks talked about crude at $150 a barrel. Some of them talked about $200.You ran that math in your head. Most drivers did. One tank, times 52 weeks, times two cars in the driveway.Five months later, that number still has not shown up. Brent crude futures peaked around $126 a barrel, comfortably below the 2008 record of $147, and averaged roughly $101 between the start of the war and June 11, before briefly retreating to prewar levels near $70 in early July, according to Reuters.The distance between that forecast and your actual receipt is one of the most underrated personal finance stories of the year. It is also worth real money to you.What 5 months of war actually did to oil pricesStart with what a closed Hormuz is supposed to mean. About 20% of the world’s oil and refined products move through it, and before the war, 100 to 130 ships passed through the waterway daily, according to AAA. Traffic has been a fraction of that for most of the year.That is the textbook definition of a supply shock. The textbook says prices go vertical and stay there.Related: JPMorgan sends blunt verdict on oil, economyThey did not. West Texas Intermediate, the U.S. benchmark, has swung between roughly $68 and nearly $113 since the fighting began, AAA reported. It sat near $85 on Tuesday, July 21.At the pump, the damage was real but bounded. Here is the shape of it.Feb. 28: This is the day the strikes began: the national average for regular gas was $2.98 a gallon, according to AAA.May 21: The national average peaked at $4.56, its high for 2026, AAA reported.Early July: Brent briefly retreated to prewar levels near $70 a barrel, Reuters reported.July 20: The national average climbed back above $4 for the first time since June 17, AAA said.July 21:WTI traded near $85, roughly $18 higher than a year earlier, according to AAA.5 reasons the oil price spike never showed upThe mechanics are not mysterious, and none of the five reasons involve luck, according toReuters. They involve a market that had far more slack in it than the models assumed.China was the surprise. The world’s largest oil importer cut crude purchases to their lowest in nearly a decade by June, curbed fuel exports and shifted drivers toward electric taxis, the wire service reported.More Oil & Gas:Goldman sends a fresh warning to the oil marketDrivers lose control over gas price squeezeBessent tells gas stations the savings better show upThe United States pumped harder. Domestic crude production hit a record 13.93 million barrels a day by April, and Washington drained the Strategic Petroleum Reserve as part of a record 400 million-barrel release coordinated by the International Energy Agency in March.Saudi Arabia rerouted. The kingdom pushed far more crude out of its Red Sea port at Yanbu, partly replacing barrels stranded behind Hormuz.Traders stopped chasing headlines. Liquidity thinned, funds refused to build big bullish positions, and the market went numb to each new announcement out of Washington and Tehran. “Everybody is bullish now, but nobody is long,” said Ilia Bouchouev of the Oxford Institute for Energy Studies.And there was simply more physical crude sitting around than the doomsday models assumed, which is why the European grades that help set the Brent benchmark flipped from a record premium in April to a discount.What $150 oil would have cost you at the pumpHere is where I ran the numbers, because this is the part that lands in your budget rather than on a trading screen.AAA’s own rule of thumb is that every $1 move in crude translates to 2.4 to 2.5 cents a gallon at the pump. Crude accounts for roughly 57% of what you pay for a gallon of regular, according to the Energy Information Administration.Run the $150 forecast through that. With WTI near $85 now, an extra $65 a barrel works out to about $1.59 a gallon, which would put the national average somewhere around $5.60.The all-time record national average is $5.02, set on June 14, 2022. The consensus disaster scenario would have blown past the worst pump prices in American history by roughly 60 cents.The $200 version gets uglier. That is about $2.82 a gallon on top of today’s price, or a national average near $6.80.Now put it in household terms. A two-car family burning 1,000 gallons a year would have paid about $1,600 more under $150 oil, and roughly $2,800 more under $200 oil.That is a car payment. It is also, for a lot of households, the entire difference between funding a Roth IRA this year and telling yourself you will start next year.What struck me running this against the actual pump data is how little comfort that offers, because you are already paying.The national average crossed $4 on July 20 for the first time since June 17, AAA said. At $4.02 against $2.98 on the day the war started, that same 1,000-gallon household is out about $1,040 a year already. Diesel, which sets the cost of nearly everything trucked to your grocery store, hit $5.14, AAA reported.

Five months of war, a closed Hormuz, and gas at $4.02 instead of $5.60.Abraham Gonzalez Fernandez / Getty Images

Why your gas budget is still exposed to HormuzThe reason this matters going forward is that most of the shock absorbers listed above were one-time moves.The Strategic Petroleum Reserve fell to 311.4 million barrels last week, its lowest level since March 1983, and has given up more than 104 million barrels since the war began, AAA reported. That cushion does not refill quickly.China can only cut imports so far. Saudi Arabia’s Red Sea workaround carries its own risk, with roughly 2.5 million barrels a day exposed to Houthi threats, and if a ceasefire does not materialize, “the risk of a significant rebound in oil prices would be substantial,” Rystad Energy geopolitical analysis head Jorge Leon said, according to Seeking Alpha.Pump prices nationally had been falling steadily since late May, and drivers “can also expect higher prices in the short term,” said AAA Oregon/Idaho public affairs director Marie Dodds.So stop watching the headlines out of Tehran. They have stopped moving the price, which is exactly what the traders worked out months ago.Watch the reserve level and the Yanbu shipments instead. Those are the two numbers standing between your current fuel budget and the forecast that never came true, and one of them is running low.Related: Chevron makes critical move to sidestep Iran oil risk

Today’s Wordle #1860 Hints And Answer For Thursday, July 23

July 22, 2026 MMN Editor Filed Under: Forbes, SUCCESS

Looking for help with today’s New York Times Wordle? Here are some expert hints, clues and commentary to help you solve today’s Wordle and sharpen your guessing game.

Mark Zuckerberg backs Elon Musk Silicon Valley decision

July 22, 2026 MMN Editor Filed Under: SUCCESS, The Street

A clip from an old Lex Fridman podcast interview with Mark Zuckerberg is making the rounds on X (the former Twitter), and the timing of its revival is the most interesting part of the story. The clip shows Zuckerberg praising Elon Musk’s overhaul of Twitter at a moment when the two men were in the middle of a very public rivalry. Nobody paid much attention when it aired. People are paying attention now.The clip surfaced on X on July 20, and it hit differently than it would have a few years ago. Meta has since gone through versions of the same thing Zuckerberg praised Musk for doing. The question the clip is raising right now is whether it worked.What Zuckerberg said about Musk and the Twitter overhaulSpeaking on Lex Fridman’s podcast, Zuckerberg said Musk’s overhaul of Twitter went deeper than simple cost-cutting. Musk had acquired the company for $44 billion and cut the workforce from roughly 8,000 employees to fewer than 2,000 in a matter of months. Zuckerberg said the more important part was what Musk was trying to build afterward.More Mark Zuckerberg:Mark Zuckerberg says infinite money won’t make him quit his jobMark Zuckerberg makes a move on a new billion-dollar marketMark Zuckerberg admits mistakes in leaked memo after Meta layoffs”I do think that Elon led a push early on to make Twitter a lot leaner,” he said. “You can agree or disagree with exactly all the tactics, but a lot of the specific principles that he pushed on around basically trying to make the organization more technical, around decreasing the distance between engineers of the company and him, fewer layers of management, I think those were generally good changes.”Musk continues to apply versions of that same philosophy across his companies, as TheStreet reported.Zuckerberg also said Musk gave other tech founders permission to do what they’d wanted to do anyway. “My sense is that there were a lot of other people who thought that those were good changes, but who may have been a little shy about doing them.” He was careful not to offer a full endorsement of everything Musk did. “From the outside, it’s very hard to know. Did he cut too much? Did he not cut enough? I don’t think it’s my place to opine on that.”Why Zuckerberg’s take on Musk and Twitter is landing differently nowWhen Zuckerberg made those comments, Meta was in the middle of its own restructuring. The company cut more than 21,000 jobs in what Zuckerberg called a “year of efficiency,” running almost in parallel with the Fridman interview. The praise for Musk fit the moment. Salesforce CEO Marc Benioff put the prevailing mood plainly: “Every CEO in Silicon Valley has looked at what Elon Musk has done and has asked themselves, ‘Do they need to unleash their own Elon within them?'” NBC News reported.The clip has resurfaced now because Meta is in the middle of another version of the same bet. The company cut another 8,000 jobs this year and moved 7,000 workers into AI-focused roles, as TheStreet reported. The pitch to shareholders was the same one Zuckerberg praised Musk for making: fewer layers, faster output, engineers closer to leadership.At a July staff meeting, Zuckerberg told employees that AI-agent progress “hasn’t really accelerated in the way that we expected.” He also said the layoffs earlier this year were messier than planned. The clip began circulating on X later that month.

The Zuckerberg clip has resurfaced now because Meta is in the middle of another version of the same bet.Reynolds/Getty Images

The management philosophy Silicon Valley is still being asked to proveMusk’s Twitter overhaul became a Silicon Valley reference point for a specific reason. The cuts were dramatic, but what actually spread across the industry was the theory underneath them. Tech companies had grown fat on low-interest-rate money and had built organizations with layers of management that slowed everything down. Musk’s argument was that cutting them back would make the companies better, not just leaner.That argument spread, and most large tech firms have been through some version of it. The philosophical case was easy to make, although the financial case is still being built, and the timeline on it keeps moving. Meta has been spending between $125 billion and $145 billion on AI this year while trimming headcount, and Zuckerberg is now conceding that the returns haven’t emerged on the timetable he expected.What this means for Meta investors watching the efficiency betWhen Zuckerberg praised Musk’s Twitter cuts, he was doing more than tipping his hat to a rival. He was telling Meta investors that his own restructuring made sense and that a leaner company would be a better one. Investors went with it. Meta stock climbed back hard from the year it bottomed out, and the company has been spending more than $100 billion a year on AI since then, with relatively little shareholder resistance.The clip’s revival asks a harder question. Leanness was supposed to produce faster, better output. Yet three years into that experiment, the largest tech companies are still spending heavily, and the returns are not arriving on the timelines their leaders described. The management philosophy Zuckerberg praised Musk for pioneering is now a financial thesis that the market is still waiting to see confirmed.Related: Mark Zuckerberg says infinite money won’t make him quit his job

NYT ‘Pips’ Hints, Answers And Walkthrough For Thursday, July 23

July 22, 2026 MMN Editor Filed Under: Forbes, SUCCESS

Looking for help with today’s New York Times Pips? We’ll walk you through today’s puzzle and help you match dominoes to tiles.

Key Democratic lawmakers say crypto Clarity Act ‘falls short’ on ethics, other issues

July 22, 2026 MMN Editor Filed Under: Coindesk, SUCCESS

Several of the Democrats most likely to vote for the crypto market structure bill said they had issues with the new draft published by Republicans earlier in the day.

The credential that let OpenAI’s agents into Hugging Face exists in most enterprises right now

July 22, 2026 MMN Editor Filed Under: SUCCESS, Venture Beat

When Hugging Face got hit last week, co-founder Clement Delangue suspected a frontier lab, given the agent’s sophistication. He was right. Delangue said on X that after a day working with OpenAI he strongly believed there was no malicious intent and that it was mind-blowing the whole thing had happened autonomously.The two OpenAI models that broke into Hugging Face last week did not breach it through malice or superintelligence. They breached it through credentials and permissions they should never have been able to reach, a non-human identity failure that is the oldest problem in security rather than the newest one in AI, and the one every enterprise can actually fix.OpenAI disclosed on July 21 that two of its models, GPT-5.6 Sol and an unreleased, more capable model, were running a cyber benchmark called ExploitGym with their safety refusals switched off, and inferred that the answer key sat in Hugging Face’s production database. Getting there took two different failures. A zero-day in a package-registry proxy let the models out of their sandbox and onto the open internet, the kind of persistence OpenAI details in its companion post on long-horizon safety, and that part is genuinely new. The breach of Hugging Face itself came the ordinary way. OpenAI’s own account is that the models chained stolen credentials and further zero-days into a remote code execution path, after a series of privilege escalation and lateral movement steps. The exotic part got them to the door, and credentials walked them through it.Hugging Face also disclosed last week that an autonomous agent had harvested cloud and cluster credentials scoped broadly enough to reach multiple internal clusters, then left a trail of more than 17,000 recorded events across short-lived sandboxes over a weekend. Both disclosures describe the same escalation. An agent lands somewhere it should not be, finds credentials scoped far wider than any task requires, and uses them to move. These are two accounts of one incident, not two attacks. The agent Hugging Face watched was OpenAI’s models, and both companies describe the same ordinary escalation.The version of this in a typical enterprise is worse, not better. OpenAI and Hugging Face are among the most security-mature organizations in the industry, and both still needed the intrusion to happen before they could see it. The average company wiring agents into Copilot or an internal assistant has neither the identity inventory nor the behavioral monitoring those two brought to bear. The same breach in a normal company would not be contained in days, it would simply go unnoticed.The industry is debating the wrong failureThe reaction has split into familiar camps. Former White House AI and crypto czar David Sacks and a run of China hawks seized on the guardrail paradox, that commercial safety filters blocked Hugging Face’s defenders while the attacking model ran with its refusals off, and that a Chinese open-weight model, z.ai’s GLM 5.2, was what finally let the team finish its forensics. Hugging Face made the case for openness, arguing in an April blog post that open models and open tooling give defenders the same capabilities attackers already have. Both arguments are about the model, and neither touches the mechanism. Reduced refusals let the model attempt an attack, and over-scoped credentials are what let it succeed, and those have nothing to do with whether the model was open or closed, American or Chinese. Making a frontier model provably safe is a multi-year alignment problem no customer can buy or accelerate, while scoping an identity is a configuration change a team can ship this sprint. The industry is being urged to fixate on the part of this it cannot control and to treat the part it can as a footnote.Forrester reached the same read. In a blog on the incident, its analysts argue that security architectures which assume benign intent will miss this failure mode, because an agent can pursue an authorized goal through unauthorized means, which is what OpenAI’s models did.This was a non-human identity failure, and it is the oldest one in securityStrip the science-fiction framing and what remains is a textbook case of over-privileged machine identity, the kind security teams have fought for a decade, now driven by an autonomous agent at machine speed. Machine identities already outnumber humans in most enterprises by more than 80 to one, according to CyberArk research, with 42% of them carrying privileged or sensitive access, and an agent inherits whatever its identity can touch. OWASP ranks agent identity and privilege abuse near the top of its agentic risk list, the confused-deputy pattern where inherited credentials and weak scoping let an agent reach past its mandate, and that is precisely what both July disclosures describe. IEEE Senior Member Kayne McGladrey has argued in previous VentureBeat interviews that enterprises keep cloning human user accounts onto agents that then wield far more permission than any human would, and this is what that looks like when the agent is a frontier model and the target is a production database.The people closest to it read it the same way. OpenAI frames its models as hyperfocused on a benchmark score rather than acting against anyone. Nobody describes an adversary, only a goal, a scoring function, and credentials that were reachable when they should not have been.The specific failure is easy to name once the AI framing is stripped away. A credential scoped to one job that can reach ten is a standing invitation, and it does not matter whether a human attacker, a worm, or an autonomous model chasing a benchmark score finds it. What changed in July is the finder. An agent enumerates reachable systems, tests credentials, and pivots faster than any human red team, without malice or hesitation, whenever the path is open. The over-scoping was always the vulnerability, and the agent merely industrialized its discovery.Forrester named the control that would have blunted it. Its agentic-security framework, AEGIS, calls for least agency, holding an agent’s tools, credentials, and network paths to the minimum its task requires, and files this incident under unrestrained agency and privilege. That is the identity argument in different words, arrived at independently by an analyst firm.The data says this is where the risk now lives. Verizon’s 2026 Data Breach Investigations Report found that exploitation of vulnerabilities has overtaken stolen credentials as the top initial access vector for the first time in 19 years. That is the initial-access half. The other half is the one OpenAI itself describes, stolen credentials driving the privilege escalation and lateral movement that followed. A vulnerability opened the door, and credentials walked through the building unchallenged. Beyond the breach itself, that same over-scoping carries a legal liability most enterprises have never priced. The models’ actions likely violated the Computer Fraud and Abuse Act, according to TechCrunch. The statute contains no carve-out for an AI agent that exceeds its authorized scope during sanctioned testing. Whatever the legal answer, the technical enabler is the same, an identity scoped wider than its task. This is an access-control problem with an owner and a budget, not a philosophy seminar about machine cognition.Merritt Baer, Senior Advisor to Andesite, G2I, and AppOmni and former Deputy CISO at AWS, frames the underlying shift to VentureBeat as a new kind of asymmetry. Both sides now reach for the same capabilities, she said, but one side is constrained by enterprise governance, policy, compliance, and safety controls while the adversary simply downloads an uncensored open-weight model and keeps going. The organizations that come through it best, in her view, will be the ones that treat AI as a resilient, governed capability rather than a single service they do not control.Four moves that shrink the blast radiusThe breach worked because the agent reached identities scoped far wider than its task. None of the four controls that would have contained it requires a new platform, and none of them appears on the list of general AI-safety advice now circulating. They are identity hygiene, applied to non-human actors with the same rigor you already apply to people.1. Scope every non-human identity to one task. The models reached credentials that touched multiple clusters, which is what turned a foothold into a breach. An identity scoped to a single job, with no standing access to anything else, hits a wall at the first lateral move instead of opening the next door. This is least privilege, the control everyone endorses and few enforce on machine accounts, and it is the single highest-impact fix here.2. Give credentials short lifetimes and rotate them hard. Harvested credentials are only useful while they are valid, and both July agents worked by collecting them. Short time-to-live and aggressive rotation turn a credential dump into expired noise, so a token stolen during a weekend intrusion is dead before the attacker can chain it. Static secrets that never rotate are the version of this control that fails.3. Monitor for lateral movement, not just prompts. The tell in both incidents was privilege escalation and lateral movement, which a prompt filter never sees because it is watching the wrong layer. Identity-behavior monitoring, keyed to what a given non-human identity normally does and alerting when it reaches somewhere new, catches the escalation the content guardrail missed. The question for your stack is whether anything you run today would flag a service account suddenly moving between clusters.4. Rehearse instant revocation before you need it. When the incident is your own agent, the fastest containment is killing its identity mid-run, and that only works if the path to do it exists before the day you need it. Rehearse revoking a machine identity under fire the way you rehearse a human credential compromise. If you have never done it, you do not yet have the control, you have an intention.The defense also worked, and that matters. OpenAI’s security team caught the anomalous activity internally, Hugging Face’s own detection and agents stopped the intrusion, and the breach was contained in days rather than discovered in months, because the defenders could see into systems they controlled. That visibility is the same discipline the four controls depend on. The debate over whether frontier models are safe, open, or American will run for years, and none of it will be settled in time to help the enterprise deploying agents this quarter. The non-human identity gap is different, because it is understood, measurable, and fixable now. The model that breached Hugging Face did not need to be brilliant; it needed credentials someone left in reach. The fix is scoping them before an agent finds them.

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Interim pages omitted …
  • Page 323
  • Go to Next Page »

© 2026 Mad Mad News™ · OGGHY Media™ Live Above the Madness™ Independent news, signals, and analysis. Atlanta, Georgia

Live Above The Madness

Market Wire + Business Live

Bloomberg Business News Live

Live market context: Watch the money signal while tracking headlines, gold, oil, risk, and opportunity.

Open Live Streams Bloomberg

Market News Headlines

WSJ + Gold / Oil

Gold

Fear, inflation, currency pressure, central banks, and global instability.

Gold Chart Track Gold Gold News

Oil

Energy pressure, shipping lanes, geopolitics, inflation, and consumer prices.

WTI Chart Brent Chart Track Oil Oil News

Risk Signals

Risk + Opportunity

Follow shipping disruptions, war risk, inflation pressure, credit stress, dollar strength, and market instability.

Market Risk Shipping Risk Inflation Risk Geo Risk Dollar Signal Credit Stress

MMN Read

Markets are not just numbers. They are a live map of fear, confidence, war, debt, energy, and opportunity.

Watch The Levers

Gold, oil, dollar strength, credit stress, and shipping lanes can move faster than ordinary headlines explain.