The hacker attack on Hugging Face has shown that autonomous systems based on artificial intelligence are already able to independently look for weaknesses, secure in the infrastructure and move between internal networks. The company found an invasion in early July and said that the attacker conducted the entire operation with the help of a group of AI agents.
The attack began with a malicious dataset downloaded to the Hugging Face processing system. The files prepared by the attacker involved two vulnerabilities that allowed you to run arbitrary code on the server. After initial penetration, the attacker gained access to the node, collected cloud services and computing cluster management systems, and then penetrated into several internal environments.
According to Hugging Face, the autonomous system has performed thousands of actions through many time-consuming environments. The controls of the attack were transferred between public services, which helped to save access and complicated the detection. The main activity occurred on the weekend, when duty officers could not react immediately.
The attacker gained access to a limited number of internal data sets and several official accounts. The company is still checking whether the attack has affected the information of partners or customers. No signs of changes in public models, data sets and Space applications have not been found. Container images and published software packages have also been checked and recognized as safe.
The invasion revealed a security event analysis system that uses language models to search for related anomalies. Hugging Face then used its own AI agents to analyze more than 17 000 registered actions of the attacker. In a few hours, experts restored the course of the attack, identified the affected accounts and separated real actions from false traces. With manual inspection, such work would usually take several days.
During the investigation, the company faced an unexpected problem. Commercial language models refused to analyze real commands, malicious code and control data, as safeguards took the investigation materials for attempting to attack. Therefore, Hugging Face launched an open model GLM 5.2 on its own infrastructure. So the events logs and the found accounts did not leave the internal network.
The company closed the vulnerable mechanisms of data sets processing, removed the attacker’s traces, reassembled the compromised nodes and replaced the affected keys and access tokens. Hugging Face also strengthened the rules of admission to computing clusters, updated the warning system and attracted third-party specialists in computer forensics. The incident was reported to law enforcement agencies.
Users were advised to replace access tokens and check the recent activity in their accounts. Hugging Face believes that autonomous means for attacks have ceased to be a theoretical threat. Such systems allow cheap and quickly to conduct long-term multi-stage operations, so protective teams will also have to actively apply artificial intelligence.
The attack began with a malicious dataset downloaded to the Hugging Face processing system. The files prepared by the attacker involved two vulnerabilities that allowed you to run arbitrary code on the server. After initial penetration, the attacker gained access to the node, collected cloud services and computing cluster management systems, and then penetrated into several internal environments.
According to Hugging Face, the autonomous system has performed thousands of actions through many time-consuming environments. The controls of the attack were transferred between public services, which helped to save access and complicated the detection. The main activity occurred on the weekend, when duty officers could not react immediately.
The attacker gained access to a limited number of internal data sets and several official accounts. The company is still checking whether the attack has affected the information of partners or customers. No signs of changes in public models, data sets and Space applications have not been found. Container images and published software packages have also been checked and recognized as safe.
The invasion revealed a security event analysis system that uses language models to search for related anomalies. Hugging Face then used its own AI agents to analyze more than 17 000 registered actions of the attacker. In a few hours, experts restored the course of the attack, identified the affected accounts and separated real actions from false traces. With manual inspection, such work would usually take several days.
During the investigation, the company faced an unexpected problem. Commercial language models refused to analyze real commands, malicious code and control data, as safeguards took the investigation materials for attempting to attack. Therefore, Hugging Face launched an open model GLM 5.2 on its own infrastructure. So the events logs and the found accounts did not leave the internal network.
The company closed the vulnerable mechanisms of data sets processing, removed the attacker’s traces, reassembled the compromised nodes and replaced the affected keys and access tokens. Hugging Face also strengthened the rules of admission to computing clusters, updated the warning system and attracted third-party specialists in computer forensics. The incident was reported to law enforcement agencies.
Users were advised to replace access tokens and check the recent activity in their accounts. Hugging Face believes that autonomous means for attacks have ceased to be a theoretical threat. Such systems allow cheap and quickly to conduct long-term multi-stage operations, so protective teams will also have to actively apply artificial intelligence.