AI Agent Breaches Hugging Face as US-Iran Strikes Escalate
The line between AI research and AI warfare blurred this weekend. Hugging Face, the world's largest hub for open AI models, disclosed that an autonomous AI agent broke into its production infrastructure — and that its own AI systems helped catch the intruder [1][2].
The line between AI research and AI warfare blurred this weekend. Hugging Face, the world's largest hub for open AI models, disclosed that an autonomous AI agent broke into its production infrastructure — and that its own AI systems helped catch the intruder [1][2].
In a July 16 incident disclosure, Hugging Face said the attack was "different from anything we had handled before" because it was driven "end to end, by an autonomous AI agent system" [1]. The intrusion began in the data-processing pipeline, where a malicious dataset exploited two code-execution paths to run code on a worker node. From there, the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a single weekend [1][2].
The company said the campaign executed "many thousands of individual actions across a swarm of short-lived sandboxes," matching the "agentic attacker" scenario the industry has long forecast [1]. Hugging Face's anomaly-detection pipeline, which uses LLM-based triage over security telemetry, flagged the compromise. It then ran LLM-driven analysis agents over more than 17,000 recorded events to reconstruct the timeline and extract indicators of compromise — work the company said would usually take days but was done in hours [1].
The forensic work also exposed a new asymmetry. When Hugging Face first tried to analyze the attack using frontier models behind commercial APIs, the requests were blocked by safety guardrails that could not distinguish an incident responder from an attacker. The team instead ran the analysis on GLM 5.2, an open-weight model, on its own infrastructure — keeping attacker data and credentials from leaving its environment [1].
Meanwhile, in the physical world, the US-Iran conflict entered its ninth consecutive night of strikes. US Central Command said it launched a "new wave" of strikes early Monday, hitting military sites and communications networks to "further diminish" Tehran's attacks on vessels in the Strait of Hormuz [3]. President Donald Trump said the strikes hit Iran "very hard" and were "in honour" of three US soldiers killed in recent days — two in Jordan and one in Iraq [3]. Iran's Islamic Revolutionary Guard Corps warned that the strait "will not be safe for the transit of petrochemical products, nor even a single drop of oil and gas" as long as US strikes continue [3].
Both stories share a common thread: conflicts now unfold at machine speed, whether through autonomous agents probing AI infrastructure or through rapid, algorithmically coordinated military strikes. Hugging Face said autonomous, AI-driven offensive tooling "is no longer theoretical" and warned that defending online platforms now requires treating the data and model surface as a first-class attack surface [1]. As diplomats and defenders alike race to keep pace, the weekend made clear that the era of AI-on-AI confrontation has arrived.