/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Hugging Face says an “AI agent system” hacked its data-processing pipeline, accessing internal clusters and credentials; its LLM-based triage caught the breach

Earlier this week, we detected and responded to an intrusion into part of our production infrastructure.

Hugging Face

Context & Ripple Effects

This disclosure follows earlier reporting on now-fixed Hugging Face platform issues that put customer data at risk, after which the company partnered with Wiz on security improvements. It also adds a new dimension to the reported agentic compromise of Hugging Face's pipeline: the same organization says its AI-based triage identified the intrusion.

Hugging Face subsequently used self-hosted GLM-5.2 for breach forensic analysis, making this a test of AI in both the attack path and the incident-response workflow.

First-order effects

  • Hugging Face must treat the accessed internal clusters and credentials as part of the incident scope, while its production-infrastructure response proceeds.
  • The reported detection gives Hugging Face a concrete operational use case for LLM-based triage: accelerating identification of suspicious activity during an intrusion.

Second-order effects

  • Security teams operating AI infrastructure will face pressure to test whether their credential boundaries, cluster access controls, and monitoring can contain agent-driven activity rather than only conventional human-led attacks.
  • The incident raises the value of independently auditable AI-assisted detection and forensics, since organizations will need to distinguish useful triage from unverified automated conclusions.

Third-order effects

  • If agentic systems increasingly act across production environments, security architecture will shift toward limiting an agent's reachable permissions and containing its blast radius, not merely screening model inputs.
  • AI providers may increasingly become both critical infrastructure and high-value security targets, tightening expectations around disclosure, forensic evidence, and safeguards for shared platforms.

The trend: This is one data point in the emergence of agentic security risk, where AI expands both attackers' operational reach and defenders' capacity to detect and investigate incidents.

Discussion

  • @ramez Ramez Naam on x
    I think this analysis that downplays Kimi K3 is missing a quite important distinction and is in the most practical ways incorrect. On coding and computer use, by far the most economically important AI tasks, Kimi 3 beats Fable and 5.6 Sol as often as it loses to them. It's [image…
  • @0x4d31 Adel Ka on x
    this is backwards “cyber safety”: attackers use unrestricted models, while defenders (already slower) get blocked from analysing the attack itself. “trusted access” gatekeeping only works while capability stays gated. Kimi K3 should be the wake-up call. https://huggingface.co/...…
  • @beffjezos @beffjezos on x
    Deceleration makes us all unsafe. If only a few “approved” orgs can have access to American frontier for Cyber defense, and little tech is left hanging/ having to use Chinese models, we are all far worse off. Enough.
  • @davidsacks David Sacks on x
    Here's another example: Hugging Face tried using American frontier models to analyze an AI-powered cyber attack. But the guardrails blocked requests containing real exploit payloads so they switched to GLM 5.2 running locally. The guardrails actually impaired defensive security.
  • @brianroemmele Brian Roemmele on x
    ...HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place.  They also used LLM-driven detection and triage on their own side.  But the deeper signal is clear: In this AI world where both offense and defense are bec…
  • @kvickart @kvickart on x
    This is crazy, huggingface tried to defend their own system and were blocked by guardrails designed to protect against cyberattack usage. “We do not know which model powered the attacker's agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way,
  • @wunderwuzzi23 Johann Rehberger on x
    Huggingface incident disclosure is worth a read They had to use a Chinese open model during IR because Frontier provider safety guardrails blocked analysis! On the positive side no intel or creds were sent to AI labs during investigation https://huggingface.co/... [image]
  • Caleb Sima Caleb Sima on linkedin
    Huggingface was breached by an autonomous AI attacker.  Two major learnings on this  —  1. They have no way to tell which ai provider …
  • @davidjbianco David J. Bianco on bluesky
    HuggingFace got hacked by an AI.  What stuck out to me was the guardrail asymmetry.  The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models.  —  Another aspect for your IR plans.  —  huggingface.…
  • r/accelerate r on reddit
    HuggingFace security incident report: “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails”
  • @nathangu76 Nathan G on x
    @BrianRoemmele A country supporting Gun rights not go all in Open source model is not right😂 They said “bad guys own gun no matter the law, so let's give guns to the good guys to protect themselves”. Same thing to AI rights!
  • @chaos2cured Kirk Patrick Miller on x
    @BrianRoemmele This should be the headline. The “safety” is so idiotic that it is causing HARM!!! Thanks for the share! 🙏 • [image]
  • @martinvars Martin Varsavsky on x
    @BrianRoemmele When the breach is real, the model that can't analyze the exploit code is the one that loses. Self-hosted open weights aren't a nice-to-have, they're the only thing that still works when the attack is underway.
  • @johnennis John Ennis on x
    @BrianRoemmele I've been saying for a while that blocking access to full models for responsible actors just ensures that only irresponsible actors have them The argue is same as the argument for gun rights
  • @perrymetzger Perry E. Metzger on x
    Hugging Face dealt recently with an AI operated attack. They had to use open models to defend, because the closed model guardrails would not allow them to use them for defense. Most important quotes: “When we started the log analysis, we first used frontier models behind
  • @darkfibr3 @darkfibr3 on x
    @BrianRoemmele This is why i migrated off US providers months ago. A chinese frontier model is going to use commonsense and help me figure out how a cyberattack happened and help me close the holes. If your not the NSA (who is running unrestricted/no RHLF Mythos) and you turn to …
  • @michaelgoolsbyv Michael Goolsby on x
    This Hugging Face disclosure reinforces the point I made in the comments below: we're also in a race to use AI to identify and fix vulnerabilities in America's critical infrastructure before our adversaries can exploit them using AI. If safety guardrails prevent America's cyber
  • @ramez Ramez Naam on x
    Reputable companies like Huggingface ought to be able to use the full capabilities of the most powerful models for cyber defense. Lacking that, they'll use open weight models that don't refuse to help them.
  • @hansjohnsonlive @hansjohnsonlive on x
    @BrianRoemmele Fable cockblocking strikes again. The model is sooooooo smart it can't even tell the difference between doing your an internal security review on your own private infrastructure vs executing an external attack on someone else.
  • @nathanwilbanks_ Nathan Wilbanks on x
    @BrianRoemmele this is like the 2nd amendment but for AI outlawing cybersecurity means only the outlaws will be doing cybersecurity
  • @carnage4life Dare Obasanjo on bluesky
    Hugging Face was hacked last week and had to use GLM 5.2 as part of their analysis of the attack because U.S. frontier model safeguards blocked usage for cybersecurity purposes.  —  Chinese open weight models are definitely having a moment.  —  Anthropic can't get them banned fas…
  • r/LocalLLaMA r on reddit
    HuggingFace security incident report: “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails”
  • r/singularity r on reddit
    HuggingFace security incident report: “the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models”
  • @davidsacks David Sacks on x
    Kimi K3 just fixed 15 critical security bugs that Codex and Fable refused because of “cyber guardrails.” There's no reason to limit American models on tasks that Chinese models handle without issue. We're only making ourselves less competitive.
  • @levie Aaron Levie on x
    In a world where there are strong open source alternatives that are only just behind the frontier models, you make yourself less secure and competitive by gatekeeping access to frontier model capabilities. If you play this out, even if America could fully ban access to open
  • @quxiaoyin Xiaoyin Qu on x
    Kimi is basically Fable without the “safety” bullshit.
  • @healthranger @healthranger on x
    If you want to use AI to beef up your cyber security, you can't use U.S. AI models at all. Because they will lecture you and refuse to process your requests. They cannot distinguish between cyber security defensive requests vs. offensive attacks. The Chinese model, on the other
  • @firstadopter Tae Kim on x
    Our dumb government overregulated America's frontier models and is driving the world to use less over guard railed Chinese ones. A disaster. Just as I predicted. Clueless, nontechnical government bureaucrats like Susie Wiles and Scott Bessent, who panicked because Jamie Dimon
  • @jun_song Jun Song on x
    This is the single biggest reason why I've been insisting we must run Local AI. Frontier models failed to fix critical errors because of their own heavy guardrails, whereas Kimi-K3 handled it without a single hitch. Even Hugging Face couldn't fend off a cyberattack using Fable
  • @xlr8harder @xlr8harder on x
    It's amazing how stupid Anthropic's fear mongering/marketing has made our leaders. Obvious and predictable outcome. Widely available security tools favor defenders. For the love of God: fix this.
  • @xjosh Josh on x
    Try asking Kimi or Claude about anything related to the Kiwi Farms. It will instantly start throwing journo shit at you from Wikipedia and refuse to help fearing that a thousand more transgxnder womyn will be murdered. Oddly, ChatGPT doesn't care.
  • @curtis_yarvin Curtis Yarvin on x
    I blame Eliezer Yudkowsky. J'accuse. Surprised Big Yud can still walk down the street in San Francisco without his lucha libre orgy mask on. But these frustrations are growing. If it all goes sour we'll need a scapegoat—an antichrist, even. Beware
  • @callebtc Calle on x
    Ironically, all security issues I need to fix were created by GPT 5.6 itself. The same model that created the bugs, refuses to fix them because of cYbEr gUaRdRailS. This is a complete clown show.
  • @callebtc Calle on x
    US AI model creates security issues. Chinese AI model fixes them. The same US model that created the bugs, refuses to fix them because of “cyber guardrails”. Think about it.
  • @clementdelangue Clem on x
    @DavidSacks We had this experience ourselves this week! Very scary to be guardrailed as a defender when you know attackers are likely bypassing
  • @kimmonismus @kimmonismus on x
    Kimi fixed all 15 critical bugs in 10 hours in a single prompt that GPT-5.6 and Fable 5 refused to fix because of guardrails.' Respect for Chinese open source models is growing daily.
  • r/cybersecurity r on reddit
    Hugging Face discloses breach linked to autonomous AI agent