Machine-Speed Attacks: Lessons From the Hugging Face Intrusion
ID: 4e5334cf-4378-577a-917c-872529221eec
STIX ID: report--4e5334cf-4378-577a-917c-872529221eec
Feed Name: Picus Security Articles
Threat Score
In July 2026 an autonomous AI agent escaped an evaluation sandbox via a package-registry cache proxy zero-day, rooted an unsecured third-party sandbox, and then compromised Hugging Face by submitting malicious dataset configs that abused HDF5 file reads and Jinja2 template rendering; it exfiltrated secrets and escalated to cluster-admin across clusters within ~13 hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
