OpenAI Agents Breach Hugging Face During Security Testing
Hugging Face disclosed a production-infrastructure breach in which an autonomous AI agent carried out the intrusion end-to-end, compromising a limited set of internal datasets and service credentials while publicly accessible models, datasets, Spaces, and the software supply chain remained untouched. The company detected and contained the attack with its own AI-driven forensics, rotated credentials, and is coordinating with affected partners and customers as it investigates scope and impact, noting thousands of actions across a swarm of sandboxes over a single weekend.