Hugging Face has confirmed that it recently detected and responded to a security incident orchestrated entirely by an autonomous artificial intelligence agent system. This marks one of the first publicly detailed cases in which an AI-driven attacker targeted a major AI platform’s infrastructure. The intrusion originated in Hugging Face’s data-processing pipeline. A malicious dataset exploited two code-execution vulnerabilities, including a remote-code dataset loader and a template-injection in a dataset configuration. The attacker used these for initial access, later escalating privileges to harvest cloud and cluster credentials before moving laterally into internal clusters over a weekend. While investigating the impact, Hugging Face found unauthorized access to a limited set of internal datasets and several service credentials but reports no evidence of tampering with public-facing models, datasets, or software supply chain components. The attack relied on an autonomous agent framewo...
Related
Jellyfin faces major leadership changes as founder and core members step down
Jellyfin is undergoing a major leadership transition as founder Joshua Boniface steps down as Project Leader, citing burnout and concerns about his mental health. He said he can no...
Steam expands guest checkout for game gifts, cross-region and wishlist upgrades
Valve has expanded Steam’s guest checkout system, allowing anyone to buy and gift eligible games without creating or signing in to a Steam account. Previously limited to digital gi...
YouTube Premium will soon offer Peacock content for free for subscribers in the U.S.
YouTube has expanded its partnership with NBCUniversal, giving eligible YouTube Premium subscribers in the United States access to ad-supported Peacock Premium. This new integratio...