• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Hugging Face Says an AI Agent Breached It, Then Fought Back With AI of Its Own

  • SOFX Staff Writer
  • July 21, 2026
(Credit: sdx15 / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

Hugging Face, one of the biggest platforms for sharing AI models, said an autonomous artificial intelligence (AI) agent carried out a cyberattack against part of its production infrastructure, allowing attackers to access internal datasets and service credentials.

The company described the incident as the first fully AI-driven intrusion it had encountered. It said it also used its AI tools to detect, analyze and investigate the attack.

“Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own,” the company said in a blog post.

Hugging Face said the attack was carried out by an autonomous agent framework that executed thousands of actions across short-lived computing environments while using self-migrating command-and-control infrastructure hosted on public services.

The company said it initially used a frontier AI model from a commercial provider, which it did not identify, to investigate the intrusion but later switched to a locally hosted large language model, the Chinese-developed open-weight GLM 5.2, after encountering restrictions that limited its cybersecurity analysis. 

“Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed,” the company said.

Hugging Face said the attackers obtained cloud and cluster credentials during the intrusion but said the exposed credentials have since been revoked and replaced. 

The company has found no evidence that public models, datasets, Spaces, or its software supply chain were compromised, and it is still investigating whether partner or customer data was affected.

The company said the incident exposed challenges for defenders using commercial AI services, noting that attackers can use unrestricted AI tools while security teams may face limitations from hosted models’ safety controls.

“We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the company said. 

Hugging Face urged organizations to prepare AI models that can run on their own infrastructure before an incident occurs.

“The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment,” the company said. 

“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,” it added. “Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace.”

Following the breach, Hugging Face said it strengthened its security measures by adding new safeguards, tightening cluster access controls and improving detection and alerting systems to speed up incident response. 

The company added that it is working with external cybersecurity forensic specialists and law enforcement agencies to investigate the breach and review its security practices.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

by SOFX Staff Writer
July 15, 2026
2

A contractor-operated plant in Mesquite, Texas, built to produce 30,000 155mm projectile components per month, has not delivered a single...

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

by SOFX Staff Writer
July 15, 2026
1

A viral video shows a Russian soldier thrown from a YakB-12.7 rotary machine gun during a training exercise after the...

ADVERTISEMENT
ADVERTISEMENT
Home Global Operations

Hugging Face Says an AI Agent Breached It, Then Fought Back With AI of Its Own

  • SOFX Staff Writer
  • July 21, 2026
(Credit: sdx15 / Shutterstock.com)
Share on FacebookShare on TwitterLinkedIn

Hugging Face, one of the biggest platforms for sharing AI models, said an autonomous artificial intelligence (AI) agent carried out a cyberattack against part of its production infrastructure, allowing attackers to access internal datasets and service credentials.

The company described the incident as the first fully AI-driven intrusion it had encountered. It said it also used its AI tools to detect, analyze and investigate the attack.

“Earlier this week, we detected and responded to an intrusion into part of our production infrastructure. This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system – and we detected and dissected it largely with AI of our own,” the company said in a blog post.

Hugging Face said the attack was carried out by an autonomous agent framework that executed thousands of actions across short-lived computing environments while using self-migrating command-and-control infrastructure hosted on public services.

The company said it initially used a frontier AI model from a commercial provider, which it did not identify, to investigate the intrusion but later switched to a locally hosted large language model, the Chinese-developed open-weight GLM 5.2, after encountering restrictions that limited its cybersecurity analysis. 

“Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary’s speed,” the company said.

Hugging Face said the attackers obtained cloud and cluster credentials during the intrusion but said the exposed credentials have since been revoked and replaced. 

The company has found no evidence that public models, datasets, Spaces, or its software supply chain were compromised, and it is still investigating whether partner or customer data was affected.

The company said the incident exposed challenges for defenders using commercial AI services, noting that attackers can use unrestricted AI tools while security teams may face limitations from hosted models’ safety controls.

“We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” the company said. 

Hugging Face urged organizations to prepare AI models that can run on their own infrastructure before an incident occurs.

“The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment,” the company said. 

“Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed,” it added. “Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace.”

Following the breach, Hugging Face said it strengthened its security measures by adding new safeguards, tightening cluster access controls and improving detection and alerting systems to speed up incident response. 

The company added that it is working with external cybersecurity forensic specialists and law enforcement agencies to investigate the breach and review its security practices.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

Russian Recruits Last 20 to 30 Minutes at the Front, the CIA Director Says, Crediting Ukraine’s Drones

by SOFX Staff Writer
July 18, 2026
2

The average Russian recruit survives just 20 to 30 minutes at the front in Ukraine before being killed or wounded,...

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

Army’s $469M Texas Munitions Plant Fails to Deliver a Single Shell Component

by SOFX Staff Writer
July 15, 2026
2

A contractor-operated plant in Mesquite, Texas, built to produce 30,000 155mm projectile components per month, has not delivered a single...

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

Viral Video Shows a Russian Gunner Flung From a Runaway Machine Gun

by SOFX Staff Writer
July 15, 2026
1

A viral video shows a Russian soldier thrown from a YakB-12.7 rotary machine gun during a training exercise after the...

Hegseth Orders Testosterone Screening for U.S. Troops

Hegseth Orders Testosterone Screening for U.S. Troops

by SOFX Staff Writer
July 16, 2026
6

War Secretary Pete Hegseth announced Wednesday that the U.S. military will begin annually screening service members aged 30 and older...

ADVERTISEMENT
ADVERTISEMENT
Next Post
New U.S. Strikes Hit Iran After Trump Vows Response for Troop Deaths

New U.S. Strikes Hit Iran After Trump Vows Response for Troop Deaths

Ukraine’s Top General May Be Ousted Next as Protests Over the Defense Minister’s Firing Grow

Ukraine's Top General May Be Ousted Next as Protests Over the Defense Minister's Firing Grow

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz