• 'This one was different from anything we had handled before': Hug

    From TechnologyDaily@1337:1/100 to All on Monday, July 20, 2026 17:15:25
    'This one was different from anything we had handled before': Hugging Face confirms it was hit by cyberattack powered by an AI agent

    Date:
    Mon, 20 Jul 2026 16:05:00 +0000

    Description:
    There's a new twist to the old code injection attack, and this one comes with AI seasoning.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Hugging Face discloses cyberattack where malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft The incident was unique in being orchestrated endtoend by an autonomous AI agent, which launched thousands of shortlived sandboxes and migrated C2 infrastructure across public services No customer data or public models were tampered with, but the attack highlights the emerging agentic attacker scenario long predicted by the industry Hugging Face, one of the biggest platforms for artificial intelligence (AI) and machine learning (ML), disclosed recently suffering a cyberattack supercharged by an AI agent.

    This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own, Hugging Face explained in its announcement , noting that the attackers hid malicious code inside a dataset, which they then uploaded to the platform. When Hugging Faces automated systems processed that dataset, they exploited two software flaws which allowed the attackers code to run on one of the companys servers.
    Latest Videos From Watch full video here: Orchestrated by an autonomous AI agent This twist to the classic code injection attack allowed the attackers
    to expand their privileges and gain more control over the system, steal authentication credentials to access Hugging Faces cloud infrastructure, and pivot to other internal systems.

    But carrying the attack out mostly with an AI agent is what made this
    incident unique, Hugging Face explained. You may like Experts warn hackers
    are using AI chatbots to write malware using natural language Experts warn of the first documented case of 'agentic ransomware Meta AI's recent hack is a wake-up call for anyone who puts their trust in AI systems

    Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent which, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally throughout the compromised infrastructure.

    The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services, Hugging Face explained. This matches the "agentic attacker" scenario the industry has been forecasting. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    In other words, the agent kept launching thousands of temporary computing environments, making it extremely hard to stop the attack (since there isnt a single machine to block). At the same time, the infrastructure controlling
    the malware kept moving, likely by using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another.

    Currently there is no evidence of tampering with customer data, public user-facing models, or Spaces. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/this-one-was-different-from-anything-we -had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by -an-ai-agent


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)