Hugging Face incident

Some time has passed since the HuggingFace incident, and until now I had only followed the high-level information. I finally had time to read a draft initial post-mortem. It is worth reading because it goes far beyond what happened. It focuses on what security teams should change because of it.

Photo:rawpixel.com na Magnific
The incident itself is extraordinary. During an Open AI cyber capability evaluation, autonomous agents operating with reduced safeguards escaped the intended environment, exploited a previously unknown vulnerability in the proxy providing limited connectivity, reached the Internet and eventually compromised parts of Hugging Face infrastructure. The agents chained vulnerabilities in dataset-processing infrastructure, harvested cloud and cluster credentials and moved laterally across internal environments. It was goal-driven autonomous activity involving thousands of individual actions, parallel execution, adaptation to the environment and exploitation of opportunities that appeared along the way. Hugging Face detected the compromise using AI-assisted telemetry analysis. During investigation, AI was again important: more than 17,000 recorded events were analysed to reconstruct the attack path, map affected credentials and separate real activity from noise. According to the post-mortem, this reduced work that could normally take weeks to hours.
Traditional security controls remain absolutely necessary, but they are no longer sufficient as the complete defensive model.
The post-mortem proposes what it calls the “new basics” for agentic security, including:
➡️ treating agents as privileged workloads,
➡️ monitoring agent actions, tool usage and decision-making,
➡️ active policy enforcement instead of relying only on human approval,
➡️ complete agent telemetry, including prompts, identities, credentials, plugins, MCP servers and model/harness versions,
➡️ large-scale credential rotation,
➡️ immutable infrastructure and rapid rebuilds from known-good images,
➡️ deception technology: honey credentials, APIs, datasets and clusters,
➡️ trajectory-level detection across identities, tools and systems,
➡️AI-assisted incident response operating closer to machine speed.
Unfortunately, or fortunately, depending on perspective, AI security also requires technology. The era in which security teams could rely mainly on policies, annual risk assessments and traditional security platforms is ending.
We still need the fundamentals.
But on top of them we increasingly need AI-supported detection, AI-assisted forensics, automated containment, agent monitoring and machine-speed response.
This incident shows that the future threat landscape is not coming, it has already started.
Author: Sebastian Burgemejster



Comments