Hugging Face Says Autonomous AI Agent Breached Its Production Infrastructure
Hugging Face, an open-source platform and community often described as the “GitHub of Machine Learning,” has disclosed unauthorized access to part of its production infrastructure in an attack the company says was carried out from start to finish by an autonomous AI agent system.
The attacker accessed a limited set of internal data and several credentials used by Hugging Face services. The company is still determining whether any customer or partner data was affected and said it will contact relevant parties if required.
According to its security incident disclosure, investigators found no evidence that public models, datasets, or Spaces were modified. Hugging Face also verified that its published packages and container images remained clean.
Malicious Dataset Opened Access to Internal Systems
The attack began when a malicious dataset exploited two code execution paths in Hugging Face’s dataset-processing system. One involved a remote-code dataset loader, while the other used template...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE