Autonomous AI Agent Breach Exposes Hugging Face Credentials

Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, stealing internal datasets and cloud credentials after exploiting a malicious dataset to trigger two code-execution vulnerabilities; the company evicted the attacker, rebuilt affected nodes, rotated credentials, and deployed enhanced detection while informing law enforcement and engaging external forensics. There is no current evidence of tampering with public models or Spaces, though the incident highlights evolving AI-driven attack risks. Users are advised to rotate access tokens and review account activity; Hugging Face also stresses having a vetted self-hosted model ready to use during incidents to avoid guardrail lockout and contain attacker data.
- Hugging Face warns an autonomous AI agent hacked its network BleepingComputer
- Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied its defense Fortune
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent The Hacker News
- Hugging Face says an AI agent carried out an end-to-end cyberattack Axios
- Hugging Face Hacked in Autonomous AI Attack SecurityWeek
Reading Insights
1
7
3 min
vs 4 min read
86%
764 → 106 words
Want the full story? Read the original article
Read on BleepingComputer