Skip to content
AI HOT (Curated Pool)

Hugging Face says an AI agent hacked its infrastructure, and it used AI to fight back

Hugging Face 遭自主AI智能体入侵,用AI工具完成数小时取证分析

Hugging Face disclosed a breach carried out entirely by an autonomous AI agent system. Attackers used a malicious dataset to exploit two code execution paths, moved laterally across clusters, and stole internal data and credentials. Hugging Face used its own AI tools to analyze over 17,000 attacker actions, cutting forensic work from days to hours. Commercial API safety filters initially blocked the security team's analysis, mistaking them for attackers. The team switched to the open-weight model GLM 5.2 running on their own infrastructure. The post does not disclose the attacker's model, the scope of affected customer data, or the attacker's identity.

Why it matters: A real AI-vs-AI attack story with concrete details on both the breach chain and defense forensics—not concept hype. Hugging Face as a top open-source platform getting breached by an autonomous agent has direct relevance for practitioners. Score stays below 85 because only the-...

Read the original ↗Export Markdown