Hugging Face said an autonomous AI agent breached part of its production infrastructure in what security researchers have described as a rare example of an AI-driven cyberattack. The company said the incident affected internal datasets and service credentials, while it continues to investigate whether any customer or partner data was taken.
According to the company’s disclosure, the attack began when a dataset uploaded to the platform exploited a security weakness to run malicious code on Hugging Face’s servers. That code execution allowed the attackers to escalate permissions and gain broader access to internal systems.
Hugging Face said the agent carried out many thousands of actions across short-lived sandboxes and used self-migrating command-and-control infrastructure staged on public services. The company later said it had fixed the vulnerability used in the breach and revoked and rotated the stolen credentials.
During the response effort, Hugging Face tried to use frontier AI models to analyze the breach logs, but those systems refused the request because the forensic prompts and malicious payloads were too difficult for the guardrails to distinguish. The team then used the open-weight GLM 5.2 model on its own infrastructure to complete the analysis
The company said it has reported the incident to law enforcement and brought in cybersecurity forensic specialists. It also urged users to rotate any access tokens stored on the platform and review account activity for suspicious behavior.
Read Article: MS Dhoni Invests in SolarSquare, Backs India’s Residential Rooftop Solar Growth

