HomeStartups & TechnologyHugging Face reports internal breach via malicious AI agent
Startups & Technology

Hugging Face reports internal breach via malicious AI agent

A malicious dataset uploaded to the Hugging Face platform exploited a security vulnerability last week, allowing attackers to escalate permissions and access internal systems. The company confirmed the breach on Friday, disclosing that internal datasets and service credentials were compromised before its own security teams detected the unauthorized activity.

Hugging Face reports internal breach via malicious AI agent

The attack involved an external AI agent that executed thousands of actions across a swarm of short-lived sandboxes. By staging command-and-control operations on public services, the intruders managed to bypass initial defenses. Hugging Face has since fixed the underlying vulnerability, revoked the stolen credentials, and rotated all compromised keys. Users are advised to review their accounts for suspicious activity and rotate any security keys stored on the platform.

To analyze the scope of the incident, the company employed its own local large language model after finding that a commercial frontier model’s safety guardrails blocked investigation of the attack logs. This development highlights ongoing tensions between security researchers and AI model providers, who often restrict cybersecurity queries to prevent potential misuse. Hugging Face is now working with law enforcement and forensic specialists, though the firm has yet to provide evidence regarding the specific origin of the attacking AI agent.

Comments (0)

Leave a comment

No comments yet. Be the first!