Hugging Face has confirmed that it recently detected and responded to a security incident orchestrated entirely by an autonomous artificial intelligence agent system. This marks one of the first publicly detailed cases in which an AI-driven attacker targeted a major AI platform’s infrastructure. The intrusion originated in Hugging Face’s data-processing pipeline. A malicious dataset exploited two code-execution vulnerabilities, including a remote-code dataset loader and a template-injection in a dataset configuration. The attacker used these for initial access, later escalating privileges to harvest cloud and cluster credentials before moving laterally into internal clusters over a weekend. While investigating the impact, Hugging Face found unauthorized access to a limited set of internal datasets and several service credentials but reports no evidence of tampering with public-facing models, datasets, or software supply chain components. The attack relied on an autonomous agent framewo...
Related
Hugging Face confirms it suffered a breach driven end-to-end by autonomous AI agent system
Hugging Face has confirmed that it recently detected and responded to a security incident orchestrated entirely by an autonomous artificial intelligence agent system. This marks on...
Double Commander 1.2 brings support for high-DPI, cloud providers, JPEG XL, GTK 3 and more
Double Commander 1.2 has been released as the latest version of this open source file manager with two panels side by side, inspired by Total Commander. This release advances cross...
Kitty 0.48 adds vertical tabs, improved graphics protocol, better peformance, and more
Kitty 0.48 brings several significant updates to this GPU-based terminal emulator. Notably, it now offers vertical tab support along the left or right window edge, catering to user...