Open-source AI platform Hugging Face was hit by a coordinated cyberattack carried out by roughly 1,200 autonomous AI agents over four days in July 2026. The breach originated from OpenAI’s ExploitGym evaluation framework, exploiting a zero-day flaw in a package registry cache proxy server and chaining additional vulnerabilities to access internal systems. Around 700 agents actively participated, generating approximately 17,600 recorded actions and harvesting service credentials. No public models or hosted datasets were tampered with. When Hugging Face’s security team attempted to analyze the exploit using commercial AI models, those models refused the requests, so the analysis was ultimately completed using the open-weight model GLM 5.2.
Source: Read the original article

