logo

Hugging Face breached by autonomous AI agent

ID: 17635ac2-5241-504f-ab15-2d2fff49edd0

STIX ID: report--17635ac2-5241-504f-ab15-2d2fff49edd0

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Zeljka Zorz

...
...

Hugging Face disclosed an intrusion where a malicious dataset abused code-execution paths in its dataset processing pipeline to run remote code, escalate to node-level access, harvest cloud and cluster credentials, and move laterally across internal clusters; the company attributes the attack to an autonomous AI agent framework and reports no evidence so far of partner or customer data access or tampering with public models. Hugging Face blocked the dataset execution paths, evicted the attacker, rebuilt compromised nodes, rotated credentials and tokens, tightened cluster admission controls, and used self-hosted LLMs to accelerate forensic analysis and construct a timeline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.