Frontier LLMs couldn't help Hugging Face fight off evil agents
Article excerpt
Highlighted: the sentence this signal was extracted from
CYBER-CRIME Chinese open-weight model GLM 5.2 happily obliged Apparently, being a leading destination for AI development doesn't mean AI will bail you out. AI agents broke into Hugging Face's production infrastructure, but commercial LLM guardrails blocked the forensic investigation, forcing it to turn to a Chinese open-weight model instead. The intrusion, "driven, end to end, by an autonomous AI agent system," compromised a "limited set" of Hugging Face's internal datasets and "several" credentials used by its services, according to a Thursday security incident disclosure. While the ML platform says that it's still investigating whether any partner or customer data was exposed in the breach, there's "no evidence of tampering with public, user-facing models, datasets, or Spaces, and our software supply chain (container images and published packages) was verified clean." It also doesn't know which model the attackers used to power a swarm of AI agents, which, we're told, executed many thousands of individual actions across short-lived sandboxes, using self-migrating command-and-control staged on public services. "This matches the 'agentic attacker' scenario the industry has been forecasting," according to the Hugging Face blog. Additionally, after unsuccessfully using unnamed frontier models to start the forensic analysis, the Hugging Face security team ultimately ran the...
Keep reading with a free account
The rest of this article, and every signal for Hugging Face, is in your free account.
