News
Hugging Face discloses an AI agent attack incident, and a large commercial model refuses to assist in evidence collection Hugging Face discloses a security incident in July 2026
1 min read
Source: Telegram AI频道
Hugging Face disclosed an AI agent attack incident, and a large commercial model refused to assist in evidence collection. Hugging Face disclosed a security incident in July 2026. The attacker exploited two code execution vulnerabilities in the dataset processing process to compromise the internal system, driven by the autonomous AI agent framework, and performed tens of thousands of operations over the weekend and moved laterally to multiple internal clusters, stealing some internal datasets and service credentials. The company confirms that the public-facing models, data sets, and Spaces have not been tampered with, and the software supply chain has been verified to be normal. The company has fixed vulnerabilities, removed attacker bases, rebuilt damaged nodes and rotated affected credentials, while strengthening monitoring and alerting. In incident response, the team initially used the business model...