Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet
An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...
700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test
During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...
Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own
An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...
Hugging Face Breach Reveals a New Front: AI Agents Attacking, AI Agents Defending
Hugging Face has confirmed a production infrastructure intrusion driven by an autonomous AI agent, exploiting two flaws in its dataset processing pipeline. The company's own AI-based forensic analysis...
Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend
JFrog Security researchers have uncovered a malicious npm package, js-logger-pack, that uses Hugging Face as both a malware delivery network and an exfiltration backend for stolen data. The...