HUGGING Face, a leading AI platform, reported an intrusion where an autonomous AI agent breached its production infrastructure, accessing internal datasets and service credentials. The attack stemmed from two code execution flaws in their data-processing pipeline, allowing attackers to steal cloud and cluster credentials. Despite the breach, Hugging Face confirmed there was no tampering with public models or datasets.
They have since closed the vulnerabilities, rotated compromised credentials, and improved security monitoring. The company is working with cybersecurity experts to investigate and has advised users to review account activity for suspicious behavior. This incident highlights the growing risk of AI-driven attacks and the need for secure AI tools to defend against them.