Overview
Hugging Face is the leading open platform for sharing machine learning models, datasets, and Spaces — core infrastructure for the open-weight and open-source AI ecosystem.
Recent Developments
- 2026-07-29: OpenAI update expands blast radius — four accounts/services in HF-linked path; modal-labs customer as early staging (2026-07-29-openai-rogue-agent-four-services)
Contradiction risk: Scope expansion does not erase HF uniqueness — other services were account compromises; HF remains the uniquely severe platform-level case in available coverage.
-
2026-07-28: ai-forensics report — popular image-editing Spaces lack platform-level guardrails against nonconsensual undress/deepfake prompts; honeypot stats published via The Verge/WIRED. Distinct from July agent-intrusion story (2026-07-28-hugging-face-deepfake-nudify-report)
-
2026-07-24: Reuters follow-up — OpenAI contacted HF ~July 20 after public HF disclosure July 16; HF had already contacted FBI (2026-07-24-openai-agent-week-delay-reuters)
-
2026-07-23: Intrusion narrative cited as catalyst for ai-kill-switch-act (2026-07-24-ai-kill-switch-act-lieu-moran)
-
2026-07-21: Hosts gated cisco-antares open-weight security SLMs (
fdtn-ai/antares-*) (2026-07-23-cisco-antares-open-weight-vuln-localization) -
2026-07-21: openai attribution — intrusion driven by OpenAI ExploitGym eval agents; HF joined trusted-access program (openai-admits-hugging-face-agent-attack)
-
2026-07-16: Disclosed production intrusion driven end-to-end by an autonomous AI agent via malicious dataset RCE paths; public models/datasets/Spaces and software supply chain verified clean; users advised to rotate tokens (hugging-face-ai-agent-security-incident)