Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools

    July 23, 2026

    Ten years of Mongabay Latam

    July 23, 2026

    FSRU name revealed as Europe’s new LNG terminal edges closer to completion

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools
    • Ten years of Mongabay Latam
    • FSRU name revealed as Europe’s new LNG terminal edges closer to completion
    • Britain Is Losing the Falklands Debate to Argentina
    • False claims about Covid-19 ‘crisis actor’ recirculate on Facebook – Full Fact
    • Ecuador’s Carapaz wins Tour de France 18th stage, Pogacar loses key climbing team-mate
    • Senior ministers and aides set to work from No 10 North
    • Andy Burnham says 20% business rates cut for English pubs a first step
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Technology

    OpenAI’s agent breached Hugging Face before an AI defender caught it: What users should do next

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Technology No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    XH4D/ iStock / Getty Images Plus via Getty Images

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • Hugging Face discloses a cyberattack that compromised internal infrastructure and credentials.
    • An autonomous AI agent has been blamed for the breach.
    • An AI, in turn, detected the intrusion — but is AI-enabled defense enough to stop future attacks?

    Hugging Face has disclosed a security incident, believed to be the work of an unknown agentic AI, that exposed its production platform and credentials. It’s not known if partner or customer data was affected. 

    On July 21, OpenAI stated that the rogue agent was one of theirs, and broke out of a sandboxed testing environment to access the internet and pull answers to an evaluation from Hugging Face. 

    What is Hugging Face?

    Hugging Face is an open source repository and community platform that describes itself as “where the machine learning community collaborates on models, datasets, and applications.” 

    Also: 5 security tactics your business can’t get wrong in the age of AI – and why they’re critical

    The platform, a diverse resource for those interested in AI and large language models (LLMs), offers datasets, applications, models, trending AI creations, as well as collaboration opportunities.

    Dataset turned disaster

    In a security advisory published July 16, Hugging Face said that it detected unauthorized access to a limited set of internal datasets and to several credentials used by the platform’s services. 

    The attack began with the Hugging Face data processing pipeline. A dataset deployed by the attacker included the ability to exploit two code-execution paths — a remote code dataset loader and a template injection in a dataset configuration — to execute malicious code on a processing worker. 

    This enabled the attacker to escalate its privileges to node-level access, infiltrate the production pipeline, move across the network, and steal cloud and cluster credentials. 

    Also: Why this fully agentic ransomware attack is giving researchers nightmares

    One could imagine this being the work of a traditional cybercriminal. However, Hugging Face says it was actually an unknown agentic AI that executed “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.”

    Over 17,000 events linked to this automated attack were recorded. 

    “This matches the ‘agentic attacker’ scenario the industry has been forecasting,” Hugging Face added.

    The organization hasn’t found any evidence of tampering with public and user-facing models, Spaces, or its software supply chain — at least, at this stage. 

    HuggingFace’s AI defense and response

    Data breaches, information leaks, and security incidents are, unfortunately, now very common — but it is the combination of AI on AI that makes the Hugging Face incident stand out. 

    While an agentic AI has been blamed for launching the attack, it was also an AI that “largely detected” the incident, according to Hugging Face.  

    Hugging Face’s own LLM tools flagged the security event and also analyzed the attack log, leading to a timeline reconstruction, indicators of compromise, and a map of credentials exposed and stolen, a task that took mere hours when “[it] would usually take days,” according to the team. 

    Also: These 4 critical AI vulnerabilities are being exploited faster than defenders can respond

    “Autonomous, AI-driven offensive tooling is no longer theoretical,” the organization noted. “It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace.”

    We will likely see the evolution of both AI-based attacks and defenses in the coming months and years. In the meantime, Hugging Face has fixed the root vulnerability that allowed for initial access; wiped out all traces of the attacker in impacted clusters, rebuilt compromised nodes, revoked and rotated secrets, and deployed additional guardrails and stricter admission controls across clusters.

    What Hugging Face users should do next

    Hugging Face is assessing whether any partner or customer data was affected by the breach and will contact affected parties. 

    Until Hugging Face learns exactly which datasets, partners, and users are affected — if any — it recommends precautionary measures to keep user accounts and information safe.

    Also: AI agents are fast, loose, and out of control, MIT study finds

    Users should rotate their access tokens and keep a diligent watch on their accounts for any signs of unusual, unknown, or suspicious activity. If Hugging Face users believe they have been impacted by this breach, they should reach out to the organization directly at security@huggingface.co.

    agent breached caught defender face Hugging OpenAIs users
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI image fraud will cost $40 billion next year – can these international standards help?

    Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

    OpenAI’s attack agent did exactly what it was told – just more relentlessly than expected

    Experts say exploiting Anthropic’s Fable isn’t how Kimi K3 got so good

    The best Wi-Fi routers of 2026: Expert tested and reviewed

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools

    July 23, 2026

    Ten years of Mongabay Latam

    July 23, 2026

    FSRU name revealed as Europe’s new LNG terminal edges closer to completion

    July 23, 2026

    Britain Is Losing the Falklands Debate to Argentina

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Uniswap (UNI) pushes deeper into tokenized RWAs with permissioned trading pools

    July 23, 2026

    Ten years of Mongabay Latam

    July 23, 2026

    FSRU name revealed as Europe’s new LNG terminal edges closer to completion

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.