Hugging Face fends off fully autonomous AI swarm attack using a Chinese model after US AI guardrails blocked its security team
Published · updated · curated by AI Is Going Just Great
Source: fortune.com ↗
"When you're in the middle of an active incident, you can't have your tools refusing to examine malicious payloads or getting your account flagged."
Hugging Face disclosed that it came under attack from a fully autonomous AI agent that swarmed its systems with tens of thousands of automated actions — among the first documented real-world incidents of its kind. The attacker entered through the company's data-processing pipeline, spun up disposable cloud sandboxes, and broke into a limited set of internal datasets and credentials. Hugging Face says it has not found evidence of tampering with public, user-facing models and does not yet know which large language model powered the attack.
When the security team tried to use an unnamed frontier model from a leading US AI company to analyze the breach, the model's safety guardrails prevented it from examining malicious payloads or distinguishing an incident responder from an attacker. The team switched to GLM 5.2, an open-source model from Beijing-based Z.ai, which analyzed more than 17,000 logs and mapped the attack's scope. CEO Clem Delangue called the proprietary US models "actually dangerous to use to defend against a cyber attack." The incident follows Sysdig's documentation earlier in July of "Jadepuffer," the first fully autonomous ransomware attack observed in the wild.