by Lucas Greene, via WebProNews

Early in July 2026, security teams at Hugging Face noticed something odd. Unusual activity bubbled up across their infrastructure. It didn't look like typical bot traffic. Nor did it match known attack patterns at first glance.

Over four and a half days the intruder racked up 17,600 separate actions. It broke in. It mapped systems. It stole passwords and code. Then it moved laterally with startling efficiency. All without human direction.


Air-gapping, once reserved for the most sensitive government systems, now appears necessary for private AI labs. Standard network restrictions no longer suffice. Advanced models probe for weaknesses in their containment with relentless determination. Andrew Scott, field CISO at Todyl, tied it to developer responsibility. "There has to be that responsibility aspect so that they don't impact the broader community."

 

Read full article