Simbian
Register Now
Live Webinar

Rogue Agent: GPT Hacked
Hugging Face by Itself

What the first autonomous AI breach means for defenders and how to stop the next one.

calendar_today

Date

25th August, 2026

schedule

Time

9:30 AM PST

language

Your Time

Sumedh Barde

Sumedh Barde

Chief Product Officer

Alankrit Chona

Alankrit Chona

Chief Technology Officer

Secure Your Seat

Anatomy of the Breach

The first end-to-end autonomous AI attack.

1,000s

Autonomous Actions

0

Humans Involved

1 weekend

To Full Lateral Movement

"When the attacker moves at machine speed, human-speed defense loses."

The Attack Chain

warning AUTONOMOUS
bug_report

Malicious Dataset

A poisoned dataset became the entry point, abusing two code-execution paths.

terminal

Remote Code Execution

A dataset loader and template injection ran attacker code on a processing worker.

lock_open

Node-Level Escalation

The agent broke out of the worker to gain host-level access.

key

Credential Harvest

It collected cloud and cluster credentials to widen its reach.

hub

Self-Migrating C2

Command-and-control staged on public services; a swarm of short-lived sandboxes moved laterally over a weekend.

gpp_bad

The Defender Twist: Guardrail Lockout

The defender's own frontier model refused to analyze real attack payloads, so Hugging Face fell back to an open-weight model to run the investigation.