
← Three Buddy Problem18 jul · 2 u 07 min
Hugging Face Just Got Hit by the First Fully Autonomous AI Attack
(Presented by Thinkst Canary: Most Companies find out way too late that they’ve been breached. Thinkst Canary changes this. Deploy Canaries and Canarytokens in minutes and then forget about them. Attackers tip their hand by touching ’em giving you the one alert, when it matters. With zero admin overhead and almost no false-positives, Canaries are deployed (and loved) on all 7 continents.)
Three Buddy Problem - Episode 105: We discuss a fascinating Hugging Face breach, where an autonomous AI agent broke out of the sandboxes, moved laterally through production, and generated 17,000 alerts before anyone caught it, and how frontier model guardrails locked the defenders out of their own investigation.
Plus, China's big AI showcase, Xi's pitch for open models and global distribution, a record 622-CVE Microsoft Patch Tuesday, and 13 years of dwell time in the Daxin backdoor.
Cast: Juan Andres Guerrero-Saade, Ryan Naraine and Costin Raiu.
Timestamps:
0:00 Introductory banter
3:51 Hugging Face discloses end-to-end agentic hack
9:42 Why Hugging Face couldn't use frontier models
13:28 AI guardrails hampering defenders
16:22 Codex vs Claude for real malware work
23:43 Flash attacks vs. going low and slow
30:27 Was it targeted, or did Hugging Face pwn itself?