根据 Hugging Face 的说法,当安全团队首次尝试使用商业 API 背后的前沿模型分析攻击日志时,遇到了障碍。因为无法区分事件响应人员和攻击者,提供商的安全防护措施阻止了请求。分析需要提交大量真实的攻击命令、漏洞利用负载和 C2 制品,而这些都触发了过滤器。Ad DEC_D_Incontent-2
“我们不知道攻击者的代理使用的是哪种模型,无论是被越狱的托管模型还是无限制的开源权重模型;无论哪种情况,攻击者都不受使用政策约束,而我们自己的取证工作却被最初尝试的托管模型的防护措施阻挡,”Hugging Face 写道:https://huggingface.co/blog/security-incident-july-2026。
公司表示,对于防御者的实际教训是,在事件发生之前,确保在自己的基础设施上运行一个强大的模型。Hugging Face 补充说,这并不是反对托管模型安全措施的理由。
Hugging Face 表示,公司已经关闭被利用的代码执行路径,撤销了攻击者的访问权限,重建了被入侵的节点,并更换了受影响的凭证。根据博客文章,公司还加强了访问控制并改进了检测系统。Hugging Face 正在与外部网络安全取证专家合作,并已向执法机关报告了该事件。作为预防措施,公司建议所有用户更换访问令牌并检查最近的账户活动。
这一事件确认,自主的、由人工智能驱动的攻击工具已不再是理论上的存在:https://the-decoder.com/uks-ai-security-institute-finds-standard-benchmarks-systematically-underestimate-what-ai-agents-can-actually-do/。根据 Hugging Face 的说法,这些工具降低了大规模、多阶段攻击行动的成本,并以机器速度运行。该公司认为,数据和模型表面需要被视为一流的攻击表面,防御者也需要拥有自己的人工智能以保持步伐。
Hugging Face 指出,商业安全过滤器阻止了其自身的取证工作,这一事实是行业应当为之做好准备的缺口。但该公司同时也是最大的开源人工智能模型平台之一,并且在将开放模型塑造成安全工作不可或缺的工具上具有明显的商业利益,因此其得出防御者绝对需要拥有自己的开放权重模型的结论,并非完全无私。
保持对人工智能的了解。清晰、有用、无废话。
关注 The Decoder 获取人工智能新闻、背景故事和专家分析。
The Decoder:https://the-decoder.com/
AI platform Hugging Face has disclosed a breach of parts of its production infrastructure that was allegedly carried out entirely by an autonomous AI agent system. The company says it detected and analyzed the attack largely with its own AI tools.
According to Hugging Face, the attackers gained unauthorized access to a limited set of internal datasets and several credentials used by Hugging Face services. The company says public models, datasets, and Spaces were not tampered with, and the software supply chain was not affected. Whether partner or customer data was compromised is still under investigation.
According to Hugging Face, the attack started at one of the weakest spots on any AI platform: the data processing pipeline. A malicious dataset:https://huggingface.co/blog/security-incident-july-2026 exploited two code execution paths in dataset processing, specifically a remote code dataset loader and a template injection in a dataset configuration. Ad
From there, the attacker escalated to node level, harvested cloud and cluster credentials, and moved laterally across multiple internal clusters over a weekend. An autonomous agent framework built on an agentic security research harness orchestrated the entire campaign, the company says. Ad DEC_D_Incontent-1
Hugging Face says it doesn't know which language model powered the attack. The system executed many thousands of individual actions through a swarm of short-lived sandboxes and used self-migrating command-and-control infrastructure running on public services. The company classifies the incident as the "agentic attacker" scenario the industry has been predicting for some time.
Hugging Face says it spotted the attack through an AI-powered anomaly detection pipeline that runs LLM-based triage on security telemetry. To make sense of the more than 17,000 recorded attacker actions, the company deployed LLM-driven analysis agents. Ad
Those agents reconstructed the timeline, extracted indicators of compromise, mapped affected credentials, and separated real damage from deception activity. Work that would normally have taken days was done in hours, the company says.
According to Hugging Face, when the security team first tried to analyze the attack logs using frontier models behind commercial APIs, it hit a wall. The providers' safety guardrails blocked the requests because they couldn't tell an incident responder from an attacker. The analysis required submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, all of which tripped the filters. Ad DEC_D_Incontent-2
The company turned to the open-weight model GLM 5.2:https://the-decoder.com/databricks-makes-chinese-open-source-model-glm-5-2-its-default-coding-engine-after-it-matched-opus-at-lower-cost/, running on its own infrastructure. According to the company, that had two advantages: no attacker data, and none of the referenced credentials ever left its own environment. Ad
"We do not know which model powered the attacker's agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried," Hugging Face wrote:https://huggingface.co/blog/security-incident-july-2026.
The practical lesson for defenders, the company says, is to have a capable model running on your own infrastructure before an incident happens. Hugging Face adds that this isn't an argument against safety measures on hosted models.
Hugging Face says it shut down the exploited code execution paths, revoked the attacker's access, rebuilt compromised nodes, and rotated affected credentials. The company also tightened access controls and improved its detection systems, according to the blog post. Hugging Face is working with external cybersecurity forensics experts and has reported the incident to law enforcement. As a precaution, the company recommends that all users rotate their access tokens and review recent account activity.
The incident confirms that autonomous, AI-driven attack tools are no longer theoretical:https://the-decoder.com/uks-ai-security-institute-finds-standard-benchmarks-systematically-underestimate-what-ai-agents-can-actually-do/. According to Hugging Face, they lower the cost of broad, multi-stage campaigns and operate at machine speed. The company argues that data and model surfaces need to be treated as first-class attack surfaces and that defenders need AI of their own to keep pace.
Hugging Face calls the fact that commercial safety filters blocked its own forensic work a gap the industry should prepare for. But the company is also one of the largest platforms for open-source AI models and has a clear business interest in framing open models as indispensable for security work, so its conclusion that defenders absolutely need their own open-weight models on hand isn't entirely selfless.
Stay in the loop on AI. Clear, useful, no fluff.
Follow The Decoder for AI news, background stories and expert analyses.
The Decoder:https://the-decoder.com/
情报判断
Aioga 编辑摘要
Hugging Face 披露部分生产基础设施遭自主 AI 智能体系统入侵。攻击者利用恶意数据集触发数据处理环节的两条代码执行路径,并获取部分内部数据集及多项服务凭证。