BleepingComputer (July 20, 2026) corroborates Hugging Face disclosure of autonomous AI agent intrusion into production infrastructure.
Attack path: malicious dataset → two dataset-processing RCE paths → worker code execution → cloud/cluster credential theft → lateral movement.
Remediation: closed vulnerable paths, rebuilt nodes, rotated credentials, improved detection, reported to law enforcement, external forensics engaged. Public assets and packages verified clean. Users urged to rotate access tokens.