menu_open Columnists
We use cookies to provide some features and experiences in QOSHE

More information  .  Close

Hugging Face Breach Signals A New Era Of AI-Powered Cyberattacks

5 0
21.07.2026

It appears that hackers are now using AI agents to launch attacks. On July 16, open-source model hosting provider Hugging Face released a blog post claiming its production infrastructure had been compromised by an autonomous AI agent.

The company said the attack was perpetrated by an autonomous agent framework, built on top of an agentic security research harness powered by an unknown LLM. During the incident, the agent is said to have executed thousands of individual actions across a “swarm” of sandboxes, resulting in unauthorized access to internal data sets and service credentials.

The open-source model provider, which is home to 2 million public models, 13 million users and over 30 percent of the Fortune 500, notes that the intrusion began when a malicious dataset abused two code execution paths to run code on a processing worker. After obtaining initial access, the agent escalated to node-level access, harvesting cloud and cluster credentials before moving into several internal clusters.

Following the breach, Hugging Face is investigating whether the breach impacted customer or partner data. If the company is correct in its assessment that the breach was led by an AI agent, it would suggest the era of the “agentic attacker” isn’t just a theoretical possibility but something that threat actors are actively exploiting.

Introducing The Agentic Attacker

Across the cybersecurity industry, anxiety over the exploitation of frontier AI models has been at fever pitch, particularly following Anthropic’s announcement of Claude Mythos Preview in April. Anthropic introduced Mythos to the world as an AI model capable of finding thousands of vulnerabilities in every major operating system and web browser.

Immediately, the company launched Project Glasswing, bringing together companies including AWS, Apple, Cisco, CrowdStrike, Microsoft and Palo Alto Networks, to try and help find ways to secure critical software before malicious actors got access to these powerful offensive capabilities.

Project Glasswing........

© Forbes