Hugging Face hacked: Blue Team turned to Chinese LLM after US models blocked
18 hours ago
- Hugging Face's production infrastructure was breached by an autonomous AI agent system, exploiting code-execution paths to gain access and harvest credentials.
- The security team used China's open-source GLM 5.2 model for forensic analysis after commercial frontier models' safety guardrails blocked incident response efforts.
- Hugging Face recommends defenders have a vetted model ready on their own infrastructure to avoid guardrail lockout and protect data from leaving the environment.
- The breach involved lateral movement into internal clusters using short-lived sandboxes, but no tampering with models, datasets, or supply chain was found.
- The incident report coincided with the release of Chinese AI models like Kimi K3, which are cheaper and perform competitively against U.S. models.