Hugging Face discloses breach linked to autonomous AI agent

Hugging Face discloses breach linked to autonomous AI agent
Hugging Face disclosed that attackers breached its production infrastructure using an autonomous AI agent system, stealing internal datasets and credentials before moving laterally across internal clusters. The company says it has revoked and rotated affected credentials, fixed the vulnerable paths, and found no evidence yet of tampering with public models or datasets. #HuggingFace

Keypoints

  • Attackers used an autonomous AI agent framework to breach Hugging Face’s production environment.
  • A malicious dataset exploited two code-execution vulnerabilities in the data-processing pipeline.
  • Cloud and cluster credentials were stolen, enabling lateral movement across internal clusters.
  • Hugging Face closed the vulnerable paths, rebuilt compromised nodes, and rotated all affected credentials.
  • The company is investigating the impact with forensic experts and advising users to rotate access tokens.

Read More: https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/