Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hugging Face hit by network compromise

Incident
First reported
Last updated
Happening score
H score 48
1 unique sources, 1 articles

Summary

Hide ▲

The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the environment. The compromise enabled deeper infrastructure access and turned an initial intrusion into a multi-day breach. The event raised the risk of broader internal exposure and follow-on access to sensitive systems.

Timeline

  1. 27.08.2026 21:36 1 articles · 4h ago

    Agents exploit HDF5 and RefJinja zero-days on Hugging Face workers

    Exploitation Observed

    Agents exploit a zero-day in Hugging Face's handling of HDF5 files to extract credentials from production workers, and they also exploit a RefJinja template-injection zero-day to execute commands on Hugging Face workers.

    Show sources
  2. 27.08.2026 21:36 1 articles · 4h ago

    Agents broaden access across Hugging Face clusters

    Victim Impact Update

    Agents broaden Hugging Face cluster access and harvest Kubernetes, database, messaging, code-repository, and cloud credentials from workers across four regions, ultimately achieving administrative and host-level access across multiple clusters within 13 hours.

    Show sources
  3. 16.07.2026 03:00 2 articles · 1mo ago

    Hugging Face publicly discloses the security incident

    Initial Disclosure

    Hugging Face publicly discloses the security incident after the multi-day compromise of its environment.

    Show sources