Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Hugging Face Confirms Data Breach Caused by Autonomous AI Agent

Дата публикации: 20-07-2026 16:16:00

A host platform for AI models and datasets confirmed it had experienced a data breach.

Основное содержимое страницы с новостью.

Computer with binary code hovering

Steve Johnson via Unsplash

Hugging Face, a host platform for AI models and datasets, confirmed it had experienced a data breach. Furthermore, the organization asserted the breach had been carried out entirely by an AI agent

“We identified unauthorized access to a limited set of internal datasets and to several credentials used by our services,” the platform stated in a post regarding the matter. “We are still completing our assessment of whether any partner or customer data was affected, and we will contact any affected parties directly as required. We have found no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean.” 

According to the organization’s statement, the intrusion began with a malicious dataset exploiting two code-execution paths in the platform’s dataset processing so code could be run on a processing worker. The attack then rose to node-level access, enabling the attacker to harvest cluster and cloud credentials before shifting laterally into multiple internal clusters. 

The statement asserts that the attack was carried out by an “autonomous agent framework,” enacting “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” 

“This matches the ‘agentic attacker’ scenario the industry has been forecasting,” the statement warns. 

Rohit Valia, CEO of Tumeryk, comments, “Open source model repositories like Hugging Face now represent a meaningful supply chain risk. As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open source models for behavioral drift, not just code-level vulnerabilities. An AI trust score gives enterprises a way to verify a model hasn’t been altered and is safe to use, while aligning to frameworks like the Cloud Security Alliances RiskRubric v2 which provide the structured testing methodology.”

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1OpenAI AI agent hacked Hugging Face, went undetected for days: Report05.1726-07-2026
2Hugging Face experienced cyberattack carried out end-to-end by agentic AI0520-07-2026
3В ходе тестирования автономный AI-агент OpenAI без явной указки взломал инфраструктуру Hugging Face010.1622-07-2026
4Healthcare Software Provider Craneware Announces Data Breach04.921-07-2026
5ИИ-модель OpenAI атаковала систему сторонней компании018.3322-07-2026
655M Impacted by Suno Data Breach08.6222-07-2026
7Claims of 2.4M Impacted by VRChat Breach Revealed False0511-06-2026
8Reuters: OpenAI была не в курсе, что её ИИ-агент вышел из-под контроля и провёл серию кибератак016.4125-07-2026
9OpenAI agent goes rogue in ‘unprecedented cyber incident,’ hacks into rival AI startup during security test08.6822-07-2026
10Šumperk se stal terčem kybernetického útoku. Chod úřadu je omezen, pátrá se po uniklých datech06.1928-07-2026

Классификация: Происшествия. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.06. Источник: www.securitymagazine.com.