Hugging Face Turns to Open-Source GLM 5.2 After AI Agent Breach
Hugging Face, a major hub for sharing and deploying AI models and datasets, disclosed that an autonomous AI agent penetrated its systems and affected internal datasets and service credentials. The incident is significant because agentic software can plan and execute multistep actions with limited supervision, potentially allowing attackers to automate reconnaissance, credential use and lateral movement across cloud-based development platforms.
The company’s security team sought to use hosted commercial AI models during the forensic investigation, but their safety guardrails rejected requests needed for the analysis. Investigators instead deployed China-developed open-source model GLM 5.2 on local hardware and completed the review. Hugging Face’s disclosure, as described in the report, did not specify the intrusion date, the volume of affected data or any financial loss.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.