ZDNET58%

OpenAI's agent breached Hugging Face before an AI defender caught it: What users should do next 64%

By Charlie Osborne45%

7/23/2026, 2:29:00 PM

BS Summary: This article contains 22 faulty reasoning types, including Unattributed Quote, Overconfidence Bias, and Confirmation Bias, with Negativity Bias as the most egregious example at 22.3% saturation with 159 hits. Analysis detected 1,162 faulty-reasoning hits from 713 analyzed words, generating a BS Score of 58.3% and a BS Rank of 64% (8,050 of 21,886 articles). This article is worse (more manipulative) than 63.20% of the article peer group.

Hugging Face has disclosed a security incident, believed to be the work of an unknown agentic AI, that exposed its production platform and credentials. 
It's not known if partner or customer data was affected. 
On July 21, OpenAI stated that the rogue agent was one of theirs, and broke out of a sandboxed testing environment to access the internet and pull answers to an evaluation from Hugging Face. 
What is Hugging Face? 
Hugging Face is an open source repository and community platform that describes itself as "where the machine learning community collaborates on models, datasets, and applications." 
Also: 5 security tactics your business can't get wrong in the age of AI - and why they're critical 
The platform, a diverse resource for those interested in AI and large language models (LLMs), offers datasets, applications, models, trending AI creations, as well as collaboration opportunities. 
Dataset turned disaster 
In a security advisory published July 16, Hugging Face said that it detected unauthorized access to a limited set of internal datasets and to several credentials used by the platform's services. 
The attack began with the Hugging Face data processing pipeline. 
A dataset deployed by the attacker included the ability to exploit two code-execution paths -- a remote code dataset loader and a template injection in a dataset configuration -- to execute malicious code on a processing worker. 
This enabled the attacker to escalate its privileges to node-level access, infiltrate the production pipeline, move across the network, and steal cloud and cluster credentials. 
Also: Why this fully agentic ransomware attack is giving researchers nightmares 
One could imagine this being the work of a traditional cybercriminal. 
However, Hugging Face says it was actually an unknown agentic AI that executed "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services." 
Over 17,000 events linked to this automated attack were recorded. 
"This matches the 'agentic attacker' scenario the industry has been forecasting," Hugging Face added. 
The organization hasn't found any evidence of tampering with public and user-facing models, Spaces, or its software supply chain -- at least, at this stage. 
HuggingFace's AI defense and response 
Data breaches, information leaks, and security incidents are, unfortunately, now very common -- but it is the combination of AI on AI that makes the Hugging Face incident stand out. 
While an agentic AI has been blamed for launching the attack, it was also an AI that "largely detected" the incident, according to Hugging Face. 
Hugging Face's own LLM tools flagged the security event and also analyzed the attack log, leading to a timeline reconstruction, indicators of compromise, and a map of credentials exposed and stolen, a task that took mere hours when "[it] would usually take days," according to the team. 
Also: These 4 critical AI vulnerabilities are being exploited faster than defenders can respond 
"Autonomous, AI-driven offensive tooling is no longer theoretical," the organization noted. 
"It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. 
Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace." 
We will likely see the evolution of both AI-based attacks and defenses in the coming months and years. 
In the meantime, Hugging Face has fixed the root vulnerability that allowed for initial access; wiped out all traces of the attacker in impacted clusters, rebuilt compromised nodes, revoked and rotated secrets, and deployed additional guardrails and stricter admission controls across clusters. 
What Hugging Face users should do next 
Hugging Face is assessing whether any partner or customer data was affected by the breach and will contact affected parties. 
Until Hugging Face learns exactly which datasets, partners, and users are affected -- if any -- it recommends precautionary measures to keep user accounts and information safe. 
Also: AI agents are fast, loose, and out of control, MIT study finds 
Users should rotate their access tokens and keep a diligent watch on their accounts for any signs of unusual, unknown, or suspicious activity. 
If Hugging Face users believe they have been impacted by this breach, they should reach out to the organization directly at security@huggingface.co. 
Article reasoning-pattern comparisonThis article: 11.1%Charlie Osborne: 1.9%ZDNET: 2.9%Confirmation Bias11.1%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 1.7%Anchoring Bias0.0%This article: 5.6%Charlie Osborne: 5.9%ZDNET: 3.1%Availability Heuristic5.6%This article: 1.5%Charlie Osborne: 1.1%ZDNET: 1.0%Representativeness Heuristic1.5%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.5%Hindsight Bias0.0%This article: 12.5%Charlie Osborne: 1.1%ZDNET: 3.2%Overconfidence Bias12.5%This article: 9.7%Charlie Osborne: 3.9%ZDNET: 4.2%Framing Effect9.7%This article: 6.0%Charlie Osborne: 3.8%ZDNET: 1.4%Loss Aversion6.0%This article: 5.9%Charlie Osborne: 1.5%ZDNET: 0.7%Status Quo Bias5.9%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Sunk Cost Effect0.0%This article: 6.0%Charlie Osborne: 1.9%ZDNET: 5.2%Optimism Bias6.0%This article: 3.8%Charlie Osborne: 3.3%ZDNET: 1.3%Pessimism Bias3.8%This article: 22.3%Charlie Osborne: 8.4%ZDNET: 4.5%Negativity Bias22.3%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 1.6%Self-Serving Bias0.0%This article: 0.0%Charlie Osborne: 0.7%ZDNET: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Actor-Observer Bias0.0%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.5%In-Group Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Out-Group Homogeneity Bias0.0%This article: 7.3%Charlie Osborne: 2.0%ZDNET: 3.9%Halo Effect7.3%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Horn Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Dunning-Kruger Effect0.0%This article: 2.0%Charlie Osborne: 2.4%ZDNET: 1.5%Recency Bias2.0%This article: 3.5%Charlie Osborne: 0.4%ZDNET: 0.4%Primacy Effect3.5%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Blind-Spot Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Ad Hominem0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Straw Man0.0%This article: 11.1%Charlie Osborne: 4.4%ZDNET: 4.7%Appeal to Authority11.1%This article: 0.0%Charlie Osborne: 0.9%ZDNET: 1.5%False Dilemma0.0%This article: 2.5%Charlie Osborne: 1.8%ZDNET: 0.6%Slippery Slope2.5%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.2%Circular Reasoning0.0%This article: 8.0%Charlie Osborne: 3.5%ZDNET: 6.5%Hasty Generalization8.0%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 0.5%Red Herring0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Bandwagon0.0%This article: 3.5%Charlie Osborne: 4.1%ZDNET: 2.0%Appeal to Emotion3.5%This article: 0.0%Charlie Osborne: 0.1%ZDNET: 0.7%Begging the Question0.0%This article: 10.1%Charlie Osborne: 1.0%ZDNET: 1.5%Post Hoc (False Cause)10.1%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Tu Quoque0.0%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 0.2%Burden of Proof0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Appeal to Nature0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.3%Composition/Division0.0%This article: 0.0%Charlie Osborne: 1.7%ZDNET: 4.9%Anecdotal0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%No True Scotsman0.0%This article: 2.2%Charlie Osborne: 2.1%ZDNET: 2.5%Ambiguity (Equivocation)2.2%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.2%Middle Ground0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Personal Incredulity0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Special Pleading0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Genetic Fallacy0.0%This article: 14.7%Charlie Osborne: 2.4%ZDNET: 0.9%Unattributed Quote14.7%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.5%Quote-first Misdirection0.0%This article: 0.0%Charlie Osborne: 3.0%ZDNET: 6.8%Biased Writer Voice0.0%This article: 10.5%Charlie Osborne: 11.1%ZDNET: 3.9%Indoctrination10.5%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Right Leaning Bias0.0%This article: 3.1%Charlie Osborne: 1.9%ZDNET: 7.5%Attempt to Sell a Product or S…3.1%

713 words analyzed.

Speakers

2speakers45%attributed speech389writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 16 words • 0.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 10 words • 0.0% coverageOpenAI • 34 words • 100.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageHugging Face • 31 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 37 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageHugging Face • 31 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageHugging Face • 14 words • 0.0% coverageHugging Face • 25 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageHugging Face • 25 words • 0.0% coverageHugging Face • 47 words • 100.0% coverageWriter's voice • 14 words • 0.0% coverageHugging Face • 11 words • 0.0% coverageHugging Face • 17 words • 0.0% coverageWriter's voice • 25 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageHugging Face • 42 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageHugging Face • 20 words • 0.0% coverageHugging Face • 27 words • 100.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 23 words • 100.0% coverageWriter's voice • 22 words • 100.0% coverage
Selected voice

OpenAI

100%flagged-word coverage
34 attributed words10% of attributed speech93% writer coverage
0%50.0%100.0%Unattributed Quote+93.8 ptsWriter: 6.2%OpenAI: 100.0%100.0%Indoctrination-12.3 ptsWriter: 12.3%OpenAI: 0.0%0.0%Attempt to Sell a Product -5.7 ptsWriter: 5.7%OpenAI: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.