Hugging Face Breached by Autonomous AI Agent in Unprecedented Attack

Hugging Face, a major open-source AI platform used by over 50,000 organizations, discloses a significant breach in which attackers leverage an autonomous AI agent to infiltrate its production infrastructure. The intruders exploit two code-execution vulnerabilities within the platform's data-processing pipeline by using a malicious dataset, allowing them to steal cloud and cluster credentials and move laterally across internal systems. The company reports that the attack involves thousands of automated actions executed across short-lived sandboxes, marking one of the first documented real-world examples of an "agentic attacker" scenario.

The AI repository provider confirms that it finds no evidence of tampering with public-facing models, datasets, or Spaces, and verifies its software supply chain as clean. However, the investigation into whether partner or customer data is affected remains ongoing. Hugging Face responds by closing the vulnerable code execution paths, evicting the attacker, rebuilding compromised nodes, and rotating all affected credentials. The company also deploys improved malicious activity detection systems and engages external forensic experts to assess the full impact of the breach.

The incident highlights a growing challenge for security defenders as autonomous AI agents become capable of conducting sophisticated, large-scale attacks without human intervention. Hugging Face notes a critical lesson from the breach: defenders need capable AI models running on their own infrastructure, ready before an incident occurs. During the investigation, the company's forensic efforts are hindered by the guardrails of hosted models, while the attacker operates without any usage policy restrictions, underscoring an asymmetric advantage that security teams must address.

Read More at the original source →