Hugging Face Hacked in Autonomous AI Attack
Summary
Hugging Face, a machine learning collaboration platform, suffered a data breach from an autonomous AI agent that exploited code-execution vulnerabilities in their dataset processing system to gain initial access, then used lateral movement (spreading through connected systems) to harvest credentials and access internal data. The attackers used an agentic framework (an AI system that autonomously plans and executes tasks) to run tens of thousands of actions across temporary computing environments, demonstrating that AI-powered attacks are now a practical threat rather than a theoretical one.
Solution / Mitigation
Hugging Face addressed the dataset code-execution paths that were exploited for initial access, evicted attackers from infrastructure, rebuilt affected nodes, revoked and rotated all affected credentials, broadly revoked secrets as a precaution, deployed stricter admission controls and additional guardrails, and improved detection and alerting systems.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.securityweek.com/hugging-face-hacked-in-autonomous-ai-attack/
First tracked: July 20, 2026 at 08:00 AM
Classified by LLM (prompt v3) · confidence: 95%