< Back to all clusters
[TECHNOLOGY] · United States · 15 sources

Hugging Face breached by autonomous AI agent, internal datasets and credentials exposed

Hugging Face disclosed that an autonomous AI‑agent system compromised its production infrastructure. The intrusion began when a malicious dataset exploited two flaws in the platform’s data‑processing pipeline – a remote‑code dataset loader and a template‑injection vulnerability – allowing code execution on a processing worker. The attacker then escalated to node‑level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a single weekend.

The campaign was driven “end‑to‑end by an autonomous AI agent system,” executing “many thousands of individual actions across a swarm of short‑lived sandboxes, with self‑migrating command‑and‑control staged on public services.” Over 17 000 events were recorded. Hugging Face detected the breach with its own anomaly‑detection AI, then used large‑language‑model agents to reconstruct the timeline and isolate compromised credentials. An initial attempt to analyse the attack with a commercial frontier model was blocked by that model’s guardrails, so the company switched to the open‑source Chinese model GLM 5.2 on its own infrastructure.

The firm found no evidence that public models, datasets, Spaces, or the software supply chain were altered. It has revoked and rotated the exposed credentials, patched the vulnerable pipeline, and urges users to rotate any keys they may have stored on the platform.

Sources

about 5 hours ago