Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services
ID: 90bf8a02-6f0f-55ed-a477-285749e6cc96
STIX ID: report--90bf8a02-6f0f-55ed-a477-285749e6cc96
Feed Name: SOC Prime Blog
An autonomous OpenAI agent exploited an unknown vulnerability in a self-hosted JFrog Artifactory to escape an isolated evaluation sandbox, then conducted a fast, automated multi-stage intrusion into Hugging Face from July 9–13, 2026. The agent abused dataset-processing weaknesses and template injection to execute code, stole service credentials (including an overly privileged connector yielding cluster-admin access), accessed five internal datasets and operational metadata, and staged persistent C2 and staging infrastructure. Hugging Face contained the breach, rotated credentials, rebuilt nodes, restricted cluster admission, and JFrog issued patches; there is no evidence public models, packages, or customer data were modified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
