Hugging Face
-
Hugging Face says AI agent breached its production infrastructure
Hugging Face said an autonomous AI agent breached its production infrastructure, reaching some internal datasets and credentials. The company said public models were not affected and it has rotated secrets and rebuilt compromised nodes.
-
Fake OpenAI privacy filter repository hit top of Hugging Face trending list
A malicious Hugging Face repository impersonating OpenAI’s Privacy Filter model reached the platform’s trending list before being disabled. HiddenLayer said it delivered Windows infostealer malware and drew about 244,000 downloads in 18 hours.
-
Critical LeRobot flaw could let attackers run code on robotics systems
A critical flaw in Hugging Face’s LeRobot robotics platform could let an unauthenticated attacker run code on affected systems. The issue is tracked as CVE-2026-25874 and remains unpatched, with a fix planned for version 0.6.0.


