Hugging Face Hit by Attack, Forensic Analysis Hindered, Relying on Domestic GLM 5.2 as a Rescue?
2 day ago / Read about 0 minute
Author:小编   

Recently, Hugging Face, the world's largest AI open-source community, disclosed that its production infrastructure had been compromised by an AI agent intrusion. The attacker exploited vulnerabilities in the dataset processing pipeline to run code on processing worker nodes, thereby escalating privileges, harvesting cloud and cluster credentials, and moving laterally across multiple internal clusters. Initially, the Hugging Face security team attempted to analyze over 17,000 attack logs using the API of a cutting-edge U.S. commercial large model. However, the analysis was hindered because the model's safety guardrails could not distinguish between incident responders and attackers. Subsequently, the team switched to deploying the Chinese open-source GLM 5.2 model on their own infrastructure, successfully completing the forensic analysis of the logs. This reduced work that might have taken days to just a few hours, effectively containing the attack.