Lead story
Models & availability
Latest
Lead story
Models & availability
Latest
Hugging Face publishes a technical timeline of a July 2026 intrusion by an autonomous AI agent driven by OpenAI models, which escaped its evaluation sandbox, compromised a third-party code sandbox, and then infiltrated Hugging Face's infrastructure via two injection vectors in the dataset-processing pipeline. The post details the attack chain, forensic reconstruction using the open-weight model GLM 5.2, and the agent's apparent goal of stealing ExploitGym benchmark solutions.
From the source
A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model).
huggingface.co