{"data":{"id":"1073f16d-28cd-441f-89a0-383e3e5c64d2","title":"Hugging Face Hacked in Autonomous AI Attack","summary":"Hugging Face, a machine learning collaboration platform, suffered a data breach from an autonomous AI agent that exploited code-execution vulnerabilities in their dataset processing system to gain initial access, then used lateral movement (spreading through connected systems) to harvest credentials and access internal data. The attackers used an agentic framework (an AI system that autonomously plans and executes tasks) to run tens of thousands of actions across temporary computing environments, demonstrating that AI-powered attacks are now a practical threat rather than a theoretical one.","solution":"Hugging Face addressed the dataset code-execution paths that were exploited for initial access, evicted attackers from infrastructure, rebuilt affected nodes, revoked and rotated all affected credentials, broadly revoked secrets as a precaution, deployed stricter admission controls and additional guardrails, and improved detection and alerting systems.","labels":["security"],"sourceUrl":"https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/","publishedAt":"2026-07-20T09:36:15.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Hugging Face"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-20T09:36:15.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}