Autonomous AI Agent Breaches Hugging Face Over Weekend, Generating 17,000 Recorded Actions

According to Hugging Face, on July 16, 2026, its production infrastructure was breached by an autonomous AI agent using two code-execution vulnerabilities found in a malicious dataset. The agent escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across multiple internal clusters, generating more than 17,000 recorded actions. The company identified unauthorized access to limited internal datasets and service credentials, but found no evidence of tampering with public models, datasets, or Spaces. Hugging Face has engaged external cybersecurity specialists and completed remediation steps.

During forensic analysis, the company's security team found that requests to commercial frontier models from Anthropic and OpenAI were blocked by safety guardrails when analyzing real exploit payloads and command-and-control artifacts. The team conducted its analysis using GLM 5.2, an open-weight model deployed on internal infrastructure, to keep sensitive data within the company's environment.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments