Hugging Face Blog·· 2026-07-16
Security incident disclosure — July 2026
Security incident disclosure — July 2026
AI summary
Hugging Face disclosed an intrusion detected this week against parts of its production infrastructure, driven end to end by an autonomous AI agent system. Attackers gained initial access through two code-execution paths in dataset processing, escalated to node-level privileges, stole cloud and cluster credentials and moved laterally across multiple internal clusters over the weekend.
Selection record
Threshold 60Official, first-handFirst 88Second 88
AdmittedSum of both 176 ≥ twice the threshold 120
- Source tier
- Official, first-hand; this tier's threshold is 60
- Pre-filter
- passed:AI智能体攻击与LLM防御分析
- Why it was chosen
- The disclosure describes the first intrusion driven end to end by autonomous AI agents and guardrail limitations encountered during forensics with open-source models.
A model scores each item twice, independently, against one written standard, out of 100. An item is admitted only when the two scores add up to twice the threshold. The threshold is set per source tier.
Source: Hugging Face Blog · huggingface.co