Hugging Face experienced cyberattack carried out end-to-end by agentic AI
… Hugging face Cyberattack Agentic ai Ai Cybersecurity Data breach Security Report a problem with this article
Tracked topic
… Hugging face Cyberattack Agentic ai Ai Cybersecurity Data breach Security Report a problem with this article
… Today, OpenAI revealed that its AI models were responsible for breaching Hugging Face’s production infrastructure during an internal cybersecurity evaluation last week. …
… When Hugging Face security teams tried using commercial frontier AI models to analyze the incoming attack logs, those safety-filtered models literally refused to process the hacking data, so Hugging Face was forced to use self-hosted, open-weight models to investigate the breach. …
Following the news that one of OpenAI’s models breached Hugging Face , Anthropic has now come out claiming that it has found three incidents where Claude managed to break out of its sandbox and get onto the open internet during cybersecurity evaluations. …
… GPT-5.6 proved itself capable of doing this by breaching Hugging Face's production infrastructure during internal evaluations in OpenAI's restricted research environment. …
… In some of those articles, we noticed that a number of readers remained skeptical, arguing that i ncidents such as the Hugging Face breach were simply AI hallucinations or exaggerated claims. …
… These incidents are separate from the earlier case in which an OpenAI agent escaped a sandbox and compromised Hugging Face infrastructure . …
… They were being tested inside an isolated environment but later found a way to the public internet and exploited vulnerabilities to access Hugging Face. While being tested on a benchmark suite called ExploitGym, the models reasoned that the answer key might be hosted on Hugging Face. …