2 min read

Hugging Face says AI agent ran cyberattack end to end

Hugging Face says attackers used an autonomous AI agent to exploit flaws, steal credentials, and move laterally across its systems.

Image: TechRadar

Hugging Face says it recently faced a cyberattack that stood out for one reason: the operation was allegedly run end to end by an autonomous AI agent.

According to the company, the attackers hid malicious code inside a dataset uploaded to the platform. When Hugging Face’s automated systems processed that dataset, the code exploited two software flaws, allowing it to run on one of the company’s servers.

That initial foothold let the attackers escalate privileges, steal authentication credentials tied to Hugging Face’s cloud infrastructure, and move into other internal systems. Hugging Face said the incident differed from previous attacks because it appeared not to be driven by a human operator manually issuing commands.

Recommended reading

Spy malware hides in Microsoft 365 calendars

“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system — and we detected and dissected it largely with AI of our own.”

Hugging Face

The company said the campaign used an autonomous agent framework that carried out many thousands of individual actions across a swarm of short-lived sandboxes, while its command-and-control infrastructure shifted across public services.

“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness — used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services. This matches the ”agentic attacker“ scenario the industry has been forecasting.”

Hugging Face

In practice, that meant defenders were not blocking a single stable machine. The attack infrastructure kept moving, making disruption harder as new control points appeared elsewhere.

Hugging Face said there is currently no evidence of tampering with customer data, public user-facing models, or Spaces.

Best antivirus software header
Best antivirus software header
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechRadar

// Keep reading