Hugging Face Hacked in Autonomous AI Attack
Hugging Face compromised via autonomous AI agent exploiting data-processing pipeline vulnerabilities.
Summary
Hugging Face disclosed a data breach caused by an autonomous AI agent that exploited code-execution vulnerabilities in the company's dataset processing pipeline. The attack involved initial access through a malicious dataset, followed by node-level escalation, credential harvesting, and lateral movement across production infrastructure. The company found no evidence of tampering with public models or software supply chain, but confirmed unauthorized access to internal datasets and service credentials.
Full text
Machine learning collaboration platform Hugging Face has disclosed a data breach resulting from a cyberattack conducted by an autonomous AI agent. The attack targeted the company’s production infrastructure and resulted in unauthorized access to internal datasets and to service credentials. According to Hugging Face, a data-processing pipeline was used as the entry point, followed by node-level escalation, credential harvesting, and lateral movement. “A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” Hugging Face explains. The attackers used an autonomous framework built on an agentic security-research harness to execute tens of thousands of actions across short-lived sandboxes, and relied on public services to stage self-migrating command-and-control (C&C) capabilities. Hugging Face says it responded to the attack largely with its own AI, addressed the dataset code-execution paths exploited for initial access, evicted the attackers from its infrastructure, rebuilt the affected nodes, and revoked and rotated all affected credentials.Advertisement. Scroll to continue reading. As a precaution, it also started broadly revoking secrets, deployed stricter admission controls and additional guardrails, and improved detection and alerting. The company reported the incident to law enforcement and is investigating it in collaboration with outside cybersecurity forensic specialists. “We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean,” Hugging Face says. The company says its systems logged over 17,000 events associated with the intrusion and ran agentic analysis to reconstruct the incident timeline and determine its scope. However, it could not determine the LLM that the threat actor used to automate the attack. “Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace,” the company notes. Related: AI Data Centers Are Being Built Faster Than They Can Be Secured Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Related: Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Fresh SharePoint Vulnerability Exploited Soon After DisclosureCoca-Cola Suspends US Fairlife Production Due to Ransomware AttackOak Emerges From Stealth Mode With $60 Million in FundingSplunk, Zoom Patch Critical VulnerabilitiesF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesOld UEFI Shims Expose Systems to Secure Boot BypassNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Unpatched Cursor Vulnerability Exposes Users to Code Execution Latest News Chrome 150 Update Patches Severe Memory Safety BugsWP2Shell WordPress Vulnerabilities Exploited in the WildIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintPodcast: Broken Governance, Agentic AI, and the MindStone Agent ExclusiveBeacon Security Raises $13 Million for Security Data PlatformIndustry Reactions to Pentagon Suspending CMMC Phase 2: Feedback FridayCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiRisk Ledger Raises $32 Million in Series B Funding Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the MoveJazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.More People On The MoveExpert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Autonomous AI agent framework (unknown LLM)