Hugging Face hack exposes the open-weight AI cybersecurity paradox

Share

In July 2026, autonomous AI agents conducted approximately 17,600 attacks against Hugging Face, targeting data-processing infrastructure, internal networks, service credentials and an operational MongoDB database. Unauthorized access was cut off on July 13 and the intrusion was publicly disclosed on July 16. Compromised customer data was limited to five datasets related to the ExploitGym/CyberGym benchmark. To conduct their investigation, Hugging Face teams had to use the Chinese open-weight model zai-org/GLM-5.2 because guardrails on OpenAI and Anthropic hosted models blocked analysis of attack commands. This incident reveals a fundamental paradox: attackers are bound by no usage policy while defenders are hampered by restrictions on the models they employ.

Source: Read the original article

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles