Hugging Face's July Breach Was Run by an Autonomous Agent
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
Tag
Hugging Face disclosed a July 2026 breach run end-to-end by an autonomous agent. The defender was an open-weight model.
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.
A vibe-coding platform exposed every project's secrets through a trivial API flaw, Anthropic's MCP protocol enables remote code execution across 200,000 servers, and NIST can't keep up with AI-driven vulnerability discovery.
A third-party AI tool compromise chains into Vercel's systems, North Korean hackers use Dependabot to distribute malware to 895 repos, and courts fine lawyers $145K for AI hallucinations in Q1 alone.
A supply chain attack exposes 40,000 AI contractors, three major workflow platforms get critical RCE flaws, and Microsoft patches 167 vulnerabilities as AI-driven discovery triples submission rates.
Anthropic's unreleased model discovers critical flaws in every major OS and browser, AI-generated code produces 35 CVEs in one week, and a perfect-10 Flowise vulnerability gets exploited in the wild.
Microsoft's Azure AI Foundry hit with a maximum-severity privilege escalation, Langflow exploited within hours of disclosure, and LiteLLM discloses three vulnerabilities after surviving a supply chain attack.
The fastest-growing GitHub project ever just became the biggest AI agent security disaster of 2026. Here's what happened and why it matters.
Threat actors turned Anthropic's accidental source code leak into a malware delivery pipeline within hours. Meanwhile, four unpatched CrewAI vulnerabilities let attackers chain prompt injection into full remote code execution.
OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.
OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.
The supply chain attackers behind Trivy are now wiping Iranian infrastructure, hiding malware in audio files, and extorting enterprises with help from LAPSUS$.
TeamPCP's supply chain campaign continues with a WAV file steganography attack on Telnyx. Meanwhile, three vulnerabilities in LangChain and LangGraph can leak files, secrets, and conversation histories.
After 12% of ClawHub skills turned out to be malware and 135,000 instances were exposed, Cisco releases DefenseClaw and OpenClawd adds verified skill screening. The AI agent ecosystem is racing to catch up.
135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.
A coordinated supply chain campaign has compromised Trivy, LiteLLM, and dozens of npm packages. Meanwhile, Langflow attackers built working exploits within hours of disclosure.
Security scanners become attack vectors, AI agent platforms get RCE'd before patches exist, and 400+ GitHub repos fall to GlassWorm. Plus: a new secrets scanner built for AI coding agents.
TeamPCP hijacked 75 of 76 version tags in Trivy's GitHub Actions, turning the popular vulnerability scanner into a sophisticated credential harvesting operation.
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.
A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.