Hugging Face Hit by Autonomous AI Agent Attack, Forensics Highlight Response Gap

Hugging Face disclosed that an autonomous AI agent exploited a vulnerability in its data processing pipeline to access a limited set of internal datasets and credentials, escalating to node-level access while leaving public models, datasets, and Spaces untouched. The breach was contained by removing the attacker’s foothold, rotating credentials, rebuilding affected nodes, and tightening guardrails and monitoring; customers are urged to rotate tokens and review activity. Forensics used Z.ai's GLM 5.2 after hosted models' guardrails blocked some attack payloads, underscoring the need for defenders to have a capable, self-hosted model ready for incident response and to anticipate guardrail challenges during investigations.
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent The Hacker News
- Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team thestack.technology
- Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens gbhackers.com
- HuggingFace hacked: How RCE Dataset Loader exploited AI playground digit.in
- AI-Driven Cyberattack Compromises Hugging Face Production Infrastructure via Autonomous Agent: Incident Analysis and Mitigation Strategies Rescana
Reading Insights
0
9
2 min
vs 3 min read
80%
500 → 101 words
Want the full story? Read the original article
Read on The Hacker News