Hugging Face Suffers AI-Driven Cyber Intrusion
Article Content
- •The intrusion was driven by an autonomous AI agent exploiting data-processing vulnerabilities.
- •Hugging Face detected the attack using AI-assisted anomaly detection, reconstructing the attack timeline quickly.
- •No public-facing data was compromised, but internal datasets and credentials were accessed.
Hugging Face reported a cyber intrusion involving an autonomous AI agent system that accessed internal datasets and credentials. The attack exploited vulnerabilities in their data-processing pipeline, using a malicious dataset to execute code on processing workers. The actor escalated access to cloud and cluster credentials, moving laterally across internal clusters over a weekend. No evidence of tampering with public models or datasets was found, and the company is assessing the impact on partner and customer data. They are collaborating with cybersecurity specialists and have reported the incident to law enforcement. Users are advised to rotate access tokens and review account activity. The attack was detected through AI-assisted anomaly detection, allowing for rapid analysis of over 17,000 events.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…