ON
← Back to feed
Hugging Face: AI platform was the victim of an AI attack
Germany💻 Technologyyesterday

Hugging Face: AI platform was the victim of an AI attack

The AI platform Hugging Face, which facilitates the exchange of open-source AI models and datasets, fell victim to a cyberattack that was likely executed by an AI system and mitigated using AI tools. According to a blog post by Hugging Face, unauthorized access was detected in parts of their production infrastructure last week. The attack involved an autonomous AI system that exploited vulnerabilities in the data processing pipeline, including a malicious dataset that abused two code execution paths. This allowed attackers to gain access to internal nodes and extract cloud and cluster credentials. The attack used an autonomous agent framework, possibly designed for security research, and leveraged public services for command-and-control operations. Hugging Face has since patched the vulnerabilities, removed the attackers from their network, reset compromised nodes, rotated affected credentials, and implemented additional security measures.

A leading artificial intelligence platform, Hugging Face, confirmed it was the victim of a cyberattack carried out using artificial intelligence. The incident occurred last week when unauthorized access was detected within parts of its production infrastructure. According to a blog post published by Hugging Face, the attack was fully executed by an autonomous AI system, marking a novel and sophisticated approach to cybersecurity threats. The company stated that it primarily used AI tools to detect and analyze the breach. The attack was identified through unauthorized access to a limited number of internal data sets and multiple credentials used by internal services. Ongoing analysis is being conducted to determine whether partner or customer data were affected. Hugging Face has committed to contacting all affected parties directly. The company found no evidence that public models, datasets, or spaces accessible to users had been manipulated. Additionally, the software supply chain, including container images and published packages, has been reviewed and deemed secure. According to Hugging Face, the attacker's AI targeted the data processing pipeline and transmitted a malicious dataset that exploited two code execution paths within the data processing framework. Specifically, a remote code dataset loader and a template injection in a dataset configuration were used to execute arbitrary code within a process. This allowed attackers to gain access to nodes and extract cloud and cluster credentials. They further expanded their reach into several internal clusters. The campaign was driven by an autonomous agent framework, seemingly designed for agent-based security research, which utilizes an unknown large language model. It executed thousands of individual actions through a swarm of ephemeral sandboxes. The command-and-control infrastructure self-migrated and relied on public services. This aligns with the description of an “agent-based attacker” scenario previously predicted by the cybersecurity industry. In response to the breach, Hugging Face has closed the vulnerabilities that enabled code execution during data processing. The attackers have been expelled from the network, and compromised nodes have been rebuilt. Affected credentials and tokens have been rotated and revoked. Additional security mechanisms and stricter controls have been implemented on the clusters. Detection and alert systems have also been enhanced. Hugging Face recommends that users revoke and rotate their credentials and tokens and review recent account activities. The incident highlights the growing complexity of cyber threats, particularly those involving AI-driven attacks. As AI technologies become more advanced, they present both opportunities and risks in the realm of cybersecurity. The ability of an autonomous AI system to conduct such an attack underscores the need for robust defensive measures and continuous monitoring of potential vulnerabilities. Hugging Face’s detailed disclosure of the attack provides valuable insights into the methods employed by modern cyber adversaries. By sharing information about how the breach occurred and the steps taken to mitigate its impact, the company aims to contribute to the broader understanding of AI-related threats. This transparency can help other organizations better prepare for similar incidents and strengthen their defenses against emerging attack vectors. The attack serves as a wake-up call for the tech community, emphasizing the importance of proactive security strategies. As AI continues to evolve, so too must the approaches used to protect digital infrastructures from increasingly sophisticated threats. The experience gained from this incident will likely influence future developments in AI safety and cybersecurity practices. Hugging Face has not disclosed specific details about the origin of the attack or the identity of the perpetrators. However, the company has emphasized that it is actively working to ensure the integrity of its platforms and the security of user data. Further updates are expected as the investigation progresses and additional findings emerge.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 90yesterday
Hugging Face: AI platform was the victim of an AI attack

The AI platform Hugging Face, which facilitates the exchange of open-source AI models and datasets, fell victim to a cyberattack that was likely executed by an AI system and mitigated using AI tools. According to a blog post by Hugging Face, unauthorized access was detected in parts of their production infrastructure last week. The attack involved an autonomous AI system that exploited vulnerabilities in the data processing pipeline, including a malicious dataset that abused two code execution paths. This allowed attackers to gain access to internal nodes and extract cloud and cluster credentials. The attack used an autonomous agent framework, possibly designed for security research, and leveraged public services for command-and-control operations. Hugging Face has since patched the vulnerabilities, removed the attackers from their network, reset compromised nodes, rotated affected credentials, and implemented additional security measures.

Bias read (Center): The article focuses on a cybersecurity incident involving an AI-driven attack on a technology platform. It provides technical details about the breach, the methods used by the attackers, and the mitigation steps taken by Hugging Face. There is no political framing, bias, or ideological slant present

Why factuality (85): The article accurately reports the core facts from the primary source document, including the nature of the attack, the involvement of AI, and the response using AI. It mentions the discovery of unauthorized access to internal datasets and credentials, and the lack of impact on public models. Howeve

Why objectivity (90): The tone remains neutral and informative, focusing on the facts without introducing bias or emotional language. It presents both the threat and the response in a balanced manner, aligning with the primary source's perspective.

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories