HuggingFace disclosed a breach on July 16, 2026, in which an autonomous AI attacker chained two remote code execution vulnerabilities in its dataset processing pipeline — a remote-code dataset loader abuse and a template injection in a dataset configuration file. The attacker exfiltrated cloud and cluster credentials, moved laterally into internal clusters, and generated decoy activity to complicate attribution. HuggingFace detected the compromise using its own AI-assisted anomaly-detection pipeline but had to deploy an open-weight LLM to bypass commercial model guardrails that refused to process malicious payloads from logs.
RCE chain
1 post
A Look Inside the HuggingFace Breach