Attackers temporarily gained unauthorized access to internal datasets and multiple credentials by exploiting two code execution vulnerabilities in Hugging Face's data processing pipeline. The incident involved remote code dataset loader and template injection, allowing lateral movement and infiltration of internal clusters over a single weekend.
AI agents are now a direct threat vector for cyberattacks, forcing AI platforms to re-evaluate security for data processing pipelines.