
Hugging Face Hit by Autonomous AI Agent Attack, Forensics Highlight Response Gap
Hugging Face disclosed that an autonomous AI agent exploited a vulnerability in its data processing pipeline to access a limited set of internal datasets and credentials, escalating to node-level access while leaving public models, datasets, and Spaces untouched. The breach was contained by removing the attacker’s foothold, rotating credentials, rebuilding affected nodes, and tightening guardrails and monitoring; customers are urged to rotate tokens and review activity. Forensics used Z.ai's GLM 5.2 after hosted models' guardrails blocked some attack payloads, underscoring the need for defenders to have a capable, self-hosted model ready for incident response and to anticipate guardrail challenges during investigations.