Hugging Face disclosed a July 2026 security breach that began with malicious datasets exploiting code-execution vulnerabilities in its data-processing pipeline, letting attackers escalate to node-level access and move laterally across internal clusters. The intrusion was notably driven by an autonomous AI agent system executing thousands of actions across sandboxed environments, and was first detected through AI-assisted anomaly detection. Hugging Face used the open-weight model GLM 5.2 to analyze over 17,000 attack events in hours rather than days, after finding that commercial API guardrails blocked forensic analysis of prompts containing real exploit payloads, and closed the vulnerabilities, rotated credentials, and added cluster controls with no evidence of tampering with public models.