discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The alliance's first named technical contribution is NVIDIA-labs OO Agent…

By Swati Khandelwal·Jul 27·thehackernews.com·3 min read

Intelligence analysis by Llama

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Image: thehackernews.com

The Open Secure AI Alliance aims to develop and share open technologies, techniques, and tools for securing software and AI agents. Its first named technical contribution is NOOA, a research framework designed to make agent behavior easier to test, trace, audit, and govern.

Why it matters

The Open Secure AI Alliance's formation and NOOA's development are significant because they address the need for securing software and AI agents. The alliance's focus on open technologies, techniques, and tools can help improve the security of AI systems and prevent potential risks.

Imagine you have a robot that can do lots of things, but you're not sure what it's doing or why. The Open Secure AI Alliance wants to make it easier to understand and control these robots, so they don't cause any problems. They're working on a special tool called NOOA that can help test and evaluate these robots, making sure they're safe and secure.

Analysis

A $60B Vote of Confidence

The Open Secure AI Alliance's formation is a significant development in the field of AI security. The alliance brings together 37 organizations, including NVIDIA, Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation. The alliance's stated scope covers the full agent stack, including identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows.

Why Cursor?

The alliance's focus on open technologies, techniques, and tools is crucial for improving the security of AI systems. The current state of AI security is characterized by a lack of transparency and accountability. AI models are often complex and difficult to understand, making it challenging to identify potential security risks. The Open Secure AI Alliance's approach addresses this issue by promoting the development and sharing of open technologies, techniques, and tools for securing AI agents.

The Road Ahead

The alliance's first named technical contribution is NOOA, an Apache 2.0 research framework designed to make agent behavior easier to test, trace, audit, and govern. NOOA provides a sandboxed environment for testing and evaluating AI models, which can help improve the security of AI systems. The framework's design allows developers to use familiar testing, tracing, version control, and refactoring workflows instead of splitting agent behavior across prompts, tool schemas, callbacks, and workflow graphs. The repository is equally direct about the risk, stating that NOOA can be configured to execute LLM-generated Python, which may transmit private data, delete files, or modify its environment. The OS-level sandbox is the containment boundary, and agents that execute generated code must run behind it.

The Hugging Face incident became the argument for the alliance's case for locally controlled defensive models. Hugging Face identified unauthorized access to a limited set of internal datasets and several credentials used by its services. The company said it ran LLM-driven analysis agents over more than 17,000 recorded actions to reconstruct the timeline, extract indicators of compromise, and map the credentials that had been touched. Commercially hosted frontier-model APIs initially rejected the attack commands, exploit payloads, and command-and-control artifacts required for the analysis. The company instead ran the open-weight GLM 5.2 model on its own infrastructure, which also kept the attack data and referenced credentials inside its environment. Its operational advice was to 'have a capable model you can run on your own infrastructure vetted and ready before an incident.' In this case, the advantage was operational control.

Key points

  • The Open Secure AI Alliance has formed to develop and share open technologies, techniques, and tools for securing software and AI agents.
  • The alliance's first named technical contribution is NOOA, an Apache 2.0 research framework designed to make agent behavior easier to test, trace, audit, and govern.
  • NOOA provides a sandboxed environment for testing and evaluating AI models, which can help improve the security of AI systems.
  • The alliance's focus on open technologies, techniques, and tools is crucial for improving the security of AI systems.
  • The Hugging Face incident became the argument for the alliance's case for locally controlled defensive models.
The Upside

The Open Secure AI Alliance's formation and NOOA's development can lead to improved AI security and reduced risks. By promoting the development and sharing of open technologies, techniques, and tools, the alliance can help improve the security of AI systems and prevent potential risks.

The Downside

The alliance's focus on open technologies, techniques, and tools may not be enough to address the complex security risks associated with AI systems. The lack of transparency and accountability in AI models can make it challenging to identify potential security risks, and the alliance's approach may not be sufficient to address these issues.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentssecuritysoftware-securitynvidiaopen-secure-ai-alliancenooa

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Jul 27, 2026

Source

thehackernews.com

Share

Topics

ai-agentssecuritysoftware-securitynvidiaopen-secure-ai-alliancenooa

Related

More from this desk

Jul 27·bleepingcomputer.com

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting variou…

Jul 27·bleepingcomputer.com

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks.

Jul 27·bleepingcomputer.com

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for DDoS attacks and traffic relay operations.

Jul 27·bleepingcomputer.com

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for the Certighost vulnerability in Windows Active Directory Certificate Services has been released, allowing attackers to potentially compromise a Windows domain. The vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday s…