Hugging Face Warns of Network Breach by Autonomous AI Agent
Hugging Face, an open-source AI and machine learning platform, disclosed a security breach where attackers accessed internal datasets and credentials using an autonomous AI agent system. The breach exploited vulnerabilities in the company's data-processing pipeline, allowing attackers to steal cloud and cluster credentials. Hugging Face has since closed the vulnerable paths, evicted the attacker, and is working with forensic experts to assess the impact. The company is investigating whether partner or customer data was affected and has advised users to rotate access tokens and review account activity.