Startups & Technology

Hugging Face reports internal breach via malicious AI agent

Hugging Face reports internal breach via malicious AI agent

The attack involved an external AI agent that executed thousands of actions across a swarm of short-lived sandboxes. By staging command-and-control operations on public services, the intruders managed to bypass initial defenses. Hugging Face has since fixed the underlying vulnerability, revoked the stolen credentials, and rotated all compromised keys. Users are advised to review their accounts for suspicious activity and rotate any security keys stored on the platform.

To analyze the scope of the incident, the company employed its own local large language model after finding that a commercial frontier model’s safety guardrails blocked investigation of the attack logs. This development highlights ongoing tensions between security researchers and AI model providers, who often restrict cybersecurity queries to prevent potential misuse. Hugging Face is now working with law enforcement and forensic specialists, though the firm has yet to provide evidence regarding the specific origin of the attacking AI agent.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!