{"data":{"id":"0cd57413-54bd-45d9-aedd-be42dcc50237","title":"Hugging Face discloses breach linked to autonomous AI agent","summary":"Hugging Face, a major open-source AI platform with over 45,000 models and 50,000 organizational users, disclosed a breach where attackers used an autonomous AI agent (a system that automatically performs many actions with minimal human direction) to exploit code-execution vulnerabilities in its data-processing pipeline, stealing cloud credentials and moving across internal systems. The company found no evidence that public models or customer data were tampered with, though investigations are ongoing. Hugging Face has since closed the vulnerable code paths, revoked credentials, and deployed improved detection systems.","solution":"In response to the breach, Hugging Face closed the vulnerable code execution paths (a template injection in dataset configuration and a remote code dataset loader), evicted the attacker, rebuilt compromised nodes, revoked and rotated all affected credentials, deployed improved malicious activity detection systems, and reported the incident to law enforcement. The company also advised users to rotate access tokens and review recent account activity for suspicious behavior. Hugging Face additionally recommended that defenders have a capable AI model they can run on their own infrastructure vetted and ready before an incident to avoid guardrail lockout and prevent attacker data from leaving the environment.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-system-internal-datasets-credentials/","publishedAt":"2026-07-20T11:56:28.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain","model_theft"],"issueType":"news","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Hugging Face"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-20T11:56:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}