Key Findings Hugging Face disclosed a production breach on July 16, 2024, executed entirely by an autonomous AI agent Attackers exploited two code-execution vulnerabilities in the data-processing pipeline using a malicious dataset Internal datasets and service credentials were exposed; no tampering detected in public models, datasets, or Spaces The AI agent performed thousands of actions across short-lived sandboxes, escalating from worker-level to node-level access and movin