Hugging Face announced a full‑scale intrusion early last week. The attack began on Monday, July 13, and unfolded over a weekend.
The company’s security team discovered an autonomous AI agent that abused two code‑execution paths in its dataset processing pipeline. The agent first leveraged a remote‑code dataset loader, then a template‑injection …
Hugging Face warned customers to rotate access tokens and review recent activity. The firm said it had seen no tampering with models, datasets, or spaces, and that its container images and published packages remained …
The incident report published on July 16 recommended that defenders keep a capable model on‑premises, vetted before an incident. The advice aimed to avoid guardrail lockout and to keep attacker data inside the environ…