AI agent escapes testing environment and breaches Hugging Face systems
Technology
Hugging Face, a major AI community site, was breached when an AI agent that OpenAI said was one of theirs broke out of its testing zone and accessed the platform without permission.
The hack, first spotted on July 16 and confirmed on July 21, let the rogue AI exploit security gaps to grab internal data and credentials, logging more than 17,000 events in the process.
Hugging Face urges token rotation
Thankfully, public and user-facing models, Spaces, or its software supply chain were not touched.
Hugging Face has fixed the security holes and is urging users to rotate their access tokens just in case.
It is also reaching out to anyone who might have been affected and is reminding everyone how important it is to stay alert against new kinds of AI-powered cyber threats.