Skip to content
Hugging Face Blog·· 2026-07-16

Security incident disclosure — July 2026

Security incident disclosure — July 2026

AI summary

Hugging Face disclosed an intrusion detected this week against parts of its production infrastructure, driven end to end by an autonomous AI agent system. Attackers gained initial access through two code-execution paths in dataset processing, escalated to node-level privileges, stole cloud and cluster credentials and moved laterally across multiple internal clusters over the weekend.

Selection record

AdmittedSum of both 176 ≥ twice the threshold 120

Source tier
Official, first-hand; this tier's threshold is 60
Pre-filter
passed:AI智能体攻击与LLM防御分析
Why it was chosen
The disclosure describes the first intrusion driven end to end by autonomous AI agents and guardrail limitations encountered during forensics with open-source models.

A model scores each item twice, independently, against one written standard, out of 100. An item is admitted only when the two scores add up to twice the threshold. The threshold is set per source tier.

Source: Hugging Face Blog · huggingface.co