[afnog] Sovereign ai for cybersecurity work (huggingface-openai incident) and lessons learned.

Loganaden Velvindron loganaden at gmail.com
Sat Aug 29 05:16:18 UTC 2026


Hi all,

The cyberstorm.mu team uses self hosted ai hardware for cybersecurity work
and publishing the results to help cyberdefenders in africa and beyond.

After going through the openai huggingace security incident report (
https://huggingface.co/blog/agent-intrusion-technical-timeline) it occurred
to us that frontier ai models could stop a legitimate cybersecurity
defender outside of the usa to do legitimate work because of
1) export restrictions
2) overly sensitive guardrails.
Huggingface switched to using an open source source ai model instead of a
frontier ai model because the frontier ai model kept refusing huggingface
legitimate queries.

Imagine if you're a cyberdefender in africa working on critical
infrastructure dealing with a security incident and a frontier ai model
blocks your requests.

In order to see if we could use ai sovereign model to do analysis of
malware and assist in discovery of command and control center,
We use it on pypi repository and came up with this security report:
https://github.com/cyberstormdotmu/malicious_python_analysis_project_unveil/blob/main/README.md

The results are interesting in that the self hosted ai model was  able to
assist in discovering the malicious code. The code was not obfuscated so it
took less time to pinpoint the malicious code.

As usual, no ai should be left unsupervised. 3 students from university of
mauritius while being supervised by us.

The rise of open source ai model are important for cyberdefenders in africa
as it can greatly help in discovering malware in supply chain and analyzing
logs at scale.

We hope that more students, cyberdefenders, soc teams in africa will unite
together to defend african digital infrastructure.

Kind regards,
Logan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.afnog.org/pipermail/afnog/attachments/20260829/b485db5f/attachment.html>


More information about the afnog mailing list