Hugging Face Hacked by AI, Fights Back with AI
Summary
Hugging Face, the popular AI platform, reports its infrastructure was hacked by an autonomous AI agent system. The attackers used a malicious dataset as an entry point, compromising internal data and stealing login credentials. Hugging Face says it detected and analyzed the attack largely with its own AI tools. These tools analyzed over 17,000 recorded actions, completing the forensic analysis in hours instead of days. The company states public models, datasets, and Spaces were not tampered with, and the software supply chain was not affected. However, whether partner or customer data was compromised is still under investigation. The attack exploited code execution paths in dataset processing, escalating to node level and moving laterally across internal clusters. Hugging Face believes an autonomous agent framework orchestrated the entire campaign. This incident highlights the emerging threat of AI-driven cyberattacks.
This is an AI-generated audio summary. Always check the original source for complete reporting.