

AI development platform Hugging Face has disclosed a significant cybersecurity breach in which an autonomous AI agent reportedly exploited vulnerabilities in its data processing pipeline to execute malicious code and gain access to the company's production infrastructure. According to the company, the attack originated from a malicious dataset uploaded to its platform, allowing the attackers to harvest cloud credentials and move across internal systems. Hugging Face said there is no evidence that public AI models or datasets were tampered with, but it is continuing to investigate whether customer or partner data was compromised.
The company stated that its AI-powered anomaly detection system identified the attack by analyzing server logs and detecting suspicious activity. For the subsequent forensic investigation, Hugging Face used an open-weight AI model hosted on its own infrastructure after encountering restrictions with another commercial frontier model. Following the incident, the company patched the exploited vulnerabilities, strengthened security controls, rotated compromised credentials, notified law enforcement authorities, and engaged external cybersecurity experts to conduct a detailed investigation.













Comments (0)
No comments yet
Be the first to comment!