Autonomous AI Agent Breached Hugging Face Production Infrastructure
Hugging Face disclosed that an autonomous AI agent system breached part of its production infrastructure after a malicious dataset exploited two code-execution paths in the company’s dataset-processing pipeline. The intrusion reportedly achieved code execution on a processing worker, escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across internal clusters at machine speed. Hugging Face said the attacker accessed a limited set of internal datasets and several service credentials, while reporting no evidence of tampering with public models, datasets, Spaces, or its software supply chain.
- 18h agoResearchers describe AI-assisted ransomware attack via exposed Langflow
- 54min agoHugging Face advises users to rotate tokens after breach


