An AI agent breached Hugging Face before an AI defender caught it: What users should do next
Follow ZDNET: Add us as a preferred source on Google.

An AI agent breached Hugging Face before an AI defender caught it: What users should do next">
Follow ZDNET: Add us as a preferred source on Google.
Hugging Face has disclosed a security incident, believed to be the work of an unknown agentic AI, that exposed its production platform and credentials. It's not known if partner or customer data was affected.
Hugging Face is an open source repository and community platform that describes itself as "where the machine learning community collaborates on models, datasets, and applications."
Also: 5 security tactics your business can't get wrong in the age of AI - and why they're critical
The platform, a diverse resource for those interested in AI and large language models (LLMs), offers datasets, applications, models, trending AI creations, as well as collaboration opportunities.
In a security advisory published July 16, Hugging Face said that it detected unauthorized access to a limited set of internal datasets and to several credentials used by the platform's services.
The attack began with the Hugging Face data processing pipeline. A dataset deployed by the attacker included the ability to exploit two code-execution paths -- a remote code dataset loader and a template injection in a dataset configuration -- to execute malicious code on a processing worker.
This enabled the attacker to escalate its privileges to node-level access, infiltrate the production pipeline, move across the network, and steal cloud and cluster credentials.
Also: Why this fully agentic ransomware attack is giving researchers nightmares
One could imagine this being the work of a traditional cybercriminal. However, Hugging Face says it was actually an unknown agentic AI that executed "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services."
Over 17,000 events linked to this automated attack were recorded.
"This matches the 'agentic attacker' scenario the industry has been forecasting," Hugging Face added.
The organization hasn't found any evidence of tampering with public and user-facing models, Spaces, or its software supply chain -- at least, at this stage.
Source: ZDNet