Hugging Face confirms it suffered a breach driven end-to-end by autonomous AI agent system

Hugging Face has confirmed that it recently detected and responded to a security incident orchestrated entirely by an autonomous artificial intelligence agent system. This marks one of the first publicly detailed cases in which an AI-driven attacker targeted a major AI platform’s infrastructure. The intrusion originated in Hugging Face’s data-processing pipeline. A malicious dataset exploited two code-execution vulnerabilities, including a remote-code dataset loader and a template-injection in a dataset configuration. The attacker used these for initial access, later escalating privileges to harvest cloud and cluster credentials before moving laterally into internal clusters over a weekend. While investigating the impact, Hugging Face found unauthorized access to a limited set of internal datasets and several service credentials but reports no evidence of tampering with public-facing models, datasets, or software supply chain components. The attack relied on an autonomous agent framewo...

Read Original

Related