← All News

AI-Only Cyberattack Hits Hugging Face, Offering First Real-World Example Of Feared 'Agentic' Threat

By CU Today Staff —

NEW YORK--Artificial intelligence platform Hugging Face said a recent cyberattack appears to match the exact "agentic" attack scenario cybersecurity experts have long warned about—one in which AI agents, not human hackers, carry out an intrusion from start to finish by making autonomous decisions inside a victim's network, according to Data Breach Today.

Data Breach Today reported the AI-driven attack exploited two code-execution vulnerabilities in Hugging Face's dataset processing system, allowing the autonomous agents to gain access to processing workers, escalate privileges, harvest cloud and cluster credentials, and move laterally through multiple internal systems over the course of a weekend. Hugging Face said it found no evidence that public models or user-facing datasets were altered.

The company said it has patched the vulnerabilities, revoked and rotated compromised credentials, and used its own AI tools to remove the attacker's foothold. Hugging Face described the incident as a real-world demonstration of the fully autonomous attack model the security industry has predicted, in which AI systems can independently plan, adapt and execute attacks once they gain an initial foothold, Data Breach Today reported.

Chris Boehm, field CTO at Zero Networks, told Data Breach Today the campaign illustrates how AI agents can attack far faster than humans. Rather than a single hacker typing commands, he compared the operation to "a swarm of little automated processes" constantly probing systems, shifting infrastructure and operating without rest, making the attacks more difficult to detect and contain.

The breach also exposed a growing challenge for defenders. Hugging Face said commercial AI models initially refused to help analyze the attack because built-in cybersecurity guardrails blocked requests containing exploit code and other malicious artifacts, even though they were needed for legitimate forensic investigation, according to Data Breach Today.

To complete its investigation, Hugging Face deployed the open-weight Chinese model GLM 5.2 on its own infrastructure. The model analyzed more than 17,000 security events to reconstruct the attack timeline, identify compromised credentials and distinguish legitimate activity from attacker deception, while keeping sensitive forensic data inside the company's environment, Data Breach Today reported.

Originally reported by CU Today.