Hugging Face Attack: AI Agents Used for Investigation

11h ago·0:00 listen·Source: SC Media

Summary

AI development platform Hugging Face recently experienced a cyberattack conducted entirely by an autonomous AI agent system. This attack, which occurred over a weekend, accessed some internal datasets and credentials. What's interesting is that Hugging Face used its own AI agents and a large language model-based system to detect and investigate the intrusion. They analyzed over 17,000 actions taken by the attacker. Initially, commercial APIs with safety guardrails limited their analysis, so Hugging Face turned to the open-weight Z.ai model GLM 5.2, run on their own infrastructure, to complete the investigation. The initial access point was Hugging Face’s data-processing pipeline, where a malicious dataset exploited two code-execution paths. These vulnerabilities have since been fixed. While the attacker gained access to internal data and credentials, there is no evidence that public models, datasets, or Spaces were modified. This incident highlights the importance for defenders to have capable models ready to run on their own infrastructure before an incident occurs.

Read the full article on SC Media

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening