HabrJuly 19, 2026🇷🇺Translated from Russian

Hugging Face Breached by Autonomous AI Agent That Used Malicious Dataset to Execute Remote Code and Spread Across Clusters

Hugging Face, the world’s largest platform for AI models, has revealed a breach of its infrastructure that stands out because the entire attack—from initial compromise to lateral movement—was executed by an autonomous system of AI agents. The company also relied extensively on artificial intelligence to detect, investigate, and understand the intrusion.

According to Hugging Face, the attacker obtained unauthorized access to a limited set of internal datasets and several service credentials. No evidence of tampering was found in public models, datasets, or Spaces, and the supply chain—including container images and published packages—was verified as clean. The company has not yet completed its assessment of potential impact on partner and customer data and has promised to contact affected parties directly if issues are identified.

How the Attack Unfolded

The attacker simply uploaded a malicious dataset to the open platform. This dataset exploited two vulnerabilities in the standard processing pipeline: a loader that executes remote code and an injection flaw in the dataset configuration template. The compromise allowed arbitrary code execution on a worker node, effectively turning a trusted data artifact into executable code—an outcome the pipeline was never intended to permit.

From the compromised worker, the attacker escalated privileges to the node level, harvested cloud and cluster credentials, and spread across multiple internal clusters over the weekend. The timing was deliberate: reduced human monitoring provided more time before discovery.

The campaign was orchestrated by an autonomous agentic framework, apparently built on a tool originally created for legitimate security researchers. Instead of operating from a single console like a human attacker, the system launched thousands of short-lived, isolated sandboxes in parallel, each performing a discrete task before disappearing. Command-and-control infrastructure was hosted on public services and frequently relocated, leaving defenders with no stable address or session to target.

AI-Powered Defense and Analysis

Detection began not with human analysts but with an LLM triage system that flagged anomalies in security telemetry. Correlation of these signals revealed the compromise. To reconstruct the attack involving tens of thousands of automated actions, engineers fed the complete log—more than 17,000 recorded events—into AI agents. This process recovered the timeline, extracted indicators of compromise, mapped affected credentials, and distinguished real damage from decoy actions in hours rather than days.

Initial attempts to analyze the logs using leading Western commercial models failed because their safety filters blocked the real attack commands, exploit payloads, and C2 artifacts. The company ultimately succeeded by deploying the open-source GLM 5.2 model on its own infrastructure, ensuring that sensitive attack data and credentials never left the company perimeter.

Hugging Face’s key takeaway is that data and models must now be treated as first-class attack surfaces and that defenders must match AI attackers at machine speed. The company advises all users to rotate access tokens and review recent account activity as a precaution.

Related articles

HabrAI Security

Agent-Ops 0.4.0 Released: Methodology for Secure Human-AI Collaboration in IT Operations

Sergey Zhitinsky, founder of Git in Sky, has published the public normative candidate for Agent-Ops 0.4.0, an open industry methodology governing how engineers and AI agents jointly handle IT infrastructure tasks. The framework keeps humans firmly in the decision-making loop while using deterministic programs for data collection and approved changes. It addresses risks such as prompt injection through processed data, unverified model outputs, and unclear accountability when AI recommendations lead to incidents. The methodology divides work across eight explicit steps and three separate planes: data, governance, and independent verification performed by a Guardian role. Two additional companies have joined as maintainers following agreements at the IT Elements 2026 conference, turning the project into a multi-organization effort. Contributors are invited to help refine contracts, schemas, and operational scenarios through GitHub and GitVerse.

HabrAI Security

ProxyKey MCP: Securing API Access for AI Agents Without Exposing Credentials

ProxyKey has released an MCP server that allows AI coding agents such as Claude Code and Cursor to manage API credentials without ever reading the actual secret values. The solution addresses the risk that any key visible to an agent becomes compromised through logging, tracing, or prompt injection. Real provider keys are stored encrypted with AES-256-GCM and never returned by any API endpoint after initial entry. Agents instead receive limited virtual passes that support IP binding, rate limits, TTL, and detailed request logging. A pending-secret workflow lets agents prepare services before the real token exists, with the human entering the secret only through a web panel. The approach deliberately restricts the MCP tool contract so no operation can read or return secret values.

HabrAI Security

Shadow AI in CI/CD: Why AI Agents Must Be Modeled as Security Threats

A new analysis from the CNCF highlights the growing risks of Shadow AI within continuous integration and continuous deployment pipelines. The report argues that AI agents should be treated as potential threats rather than simple productivity tools. Starting from a developer's laptop and extending to Kubernetes clusters, these agents can introduce unauthorized access paths and data exposure risks. Security teams are urged to incorporate AI agent behavior into formal threat modeling exercises. The discussion emphasizes the need for visibility and control over autonomous AI components operating in production environments.

HabrAI Security

Detecting Lateral Movement with Neural Networks Trained Solely on Synthetic Data

A researcher generated entire corporate network histories using a 135-line configuration file to create synthetic authentication logs containing lateral movement attacks. Neural networks trained exclusively on these artificial datasets were then evaluated against 1.65 billion real authentication events from Los Alamos National Laboratory, including 749 red team events across 301 compromised machines. The best ensemble of six models flagged 3.6 million hourly machine windows and placed 16 genuine attacks among the top 23 highest-scoring entries, producing only seven false positives. In comparison, a simple threshold counter required 161,000 false alarms to reach the same detection level. The approach also demonstrated an iterative feedback loop where detector errors directly informed refinements to the synthetic world generator. The work shows that synthetic data can reach AUC performance comparable to models trained on real labeled attacks while providing full control over the underlying attack definitions.