THREAT OPS › Threat News › The Hugging Face Hack Was Cheap Persistence at Work
The Hugging Face Hack Was Cheap Persistence at Work
<p>The OpenAI-Hugging Face incident is being discussed primarily as a zero-day story. That framing is too narrow.</p> <p>The agent discovered and exploited previously unknown vulnerabilities. The more consequential development came afterward. Over a four-and-a-half-day campaign, it carried out <a href="https://huggingface.co/blog/agent-intrusion-technical-timeline">roughly 17,600 actions</
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-65617cve
- CVE-2026-65923cve
- CVE-2026-66018cve
- https://huggingface.co/blog/agent-intrusion-technical-timelineurl
- https://openai.com/index/hugging-face-model-evaluation-security-incident/url
- https://www.aisi.gov.uk/blog/how-far-behind-the-frontier-are-leading-open-weight-models-on-cyberurl
- https://hai.stanford.edu/news/ai-index-2025-state-of-ai-in-10-chartsurl
- https://www.anthropic.com/news/disrupting-AI-espionageurl
- https://www.aisi.gov.uk/blog/how-fast-is-autonomous-ai-cyber-capability-advancingurl
- https://labs.cloudsecurityalliance.org/research/csa-research-note-huggingface-autonomous-agent-breach-202607/url
- https://www.csoonline.com/article/4202852/openai-rogue-ai-agents-attack-expanded-beyond-hugging-face.htmlurl
Original source: https://www.recordedfuture.com/blog/hugging-face-cheap-persistence