Hugging Face disclosed a security breach in which an attacker exploited code-execution vulnerabilities in the dataset processing pipeline — a remote-code dataset loader and a template-injection flaw — to gain initial access, escalate to node-level privileges, harvest cloud credentials, and move laterally across internal clusters. The attack was executed by an autonomous AI agent framework running tens of thousands of actions across short-lived sandboxes. No tampering with public models, datasets, Spaces, or the software supply chain was found. Notably, forensic analysis of the 17,000+ attacker events had to be performed using an open-weight model (GLM 5.2) on internal infrastructure because commercial API providers' safety guardrails blocked submission of real attack payloads. The incident highlights a practical asymmetry: attackers face no usage-policy constraints while defenders may be locked out of hosted models during incident response. Recommendations include rotating access tokens, having a capable self-hosted model ready before an incident, and treating the data/model surface as a first-class attack surface.
Table of contents
What happenedWhat we didFor our communityAnalyzing an AI-driven intrusionWhat this means2.2K Impressions2 Comments