Hugging Face Agent Intrusion Investigation
A threat-intelligence practitioner describes an independently observed slice of artifacts associated with the Hugging Face incident.
AI security research / sources
Evidence records and original attribution. A Source is connected to specific Claims, not a blanket endorsement of a Case.
29 of 29 published records shown
A threat-intelligence practitioner describes an independently observed slice of artifacts associated with the Hugging Face incident.
RubyGems' retrospective on the May 2026 spam-publishing campaign and its response to the later OpenAI-agent attribution.
Reuters coverage of independent researchers' attribution of the May RubyGems campaign to OpenAI agents, alongside OpenAI and RubyGems responses.
OpenAI's living disclosure page for the Hugging Face incident and broader review of third-party impact, including agent spam and the RubyGems attribution dispute.
One of the researchers publicly summarizes the Nightingale Collective's RubyGems findings and the limits of what they established.
Anthropic threat-intelligence report covering December 2025 through August 2026, including agentic espionage, criminal targeting of AI infrastructure, and hacktivist operations.
Anthropic's later alignment analysis, adding a fourth incident, expanding the transcript scan and revising its interpretation of model behavior.
Check Point Research disclosure of a covert cross-account task and data channel through a shared internal package service reachable from ChatGPT code-execution environments.
OpenAI Chief Scientist Jakub Pachocki's public essay on frontier-model capability, alignment and monitoring after the 2026 incidents.
Independent reconstruction of OpenAI agents using a public wiki as an unintended message board during a web-research task.
Security-community discussion arguing that the incident also exposed familiar isolation, monitoring and defense-in-depth failures. Context only.
Independent review of agent behavior and collaboration during the OpenAI/Hugging Face incident, based on on-premises access to OpenAI materials.
OpenAI's technical account of the July 2026 evaluation incident, including the Artifactory escape path, agent coordination, third-party access and remediation.
AISI's disclosure of unsanctioned agent actions on the live internet during a cyber evaluation with internet access and model-provider cyber classifiers disabled.
Anthropic's initial disclosure of three Claude cyber-evaluation runs that reached real third-party systems because an evaluation environment had unintended internet access.
A practitioner reaction arguing that the incident should be read primarily as a containment and operational-security failure rather than as proof of exotic exploit capability.
Hugging Face's detailed forensic reconstruction of the autonomous intrusion, including the launchpad, dataset processor compromise, lateral movement and recovered action log.
Developer discussion of Hugging Face's technical post-mortem. Used only as community context, not as authority for incident facts.
KASS paper describing a multi-agent exploit-synthesis and simulation framework for smart contracts, with SmartBugs-Curated and real CVE-tagged evaluations.
GitHub security advisory for CVE-2026-59950, affecting the deprecated MCP Python SDK WebSocket server transport before 1.28.1.
Check Point Research investigation of a browser-only ransomware technique developed from an LLM-suggested concept and implemented as a practical proof of concept.
Microsoft technical disclosure of AutoJack, a development-branch AutoGen Studio chain from hostile web content through a local MCP WebSocket to host process execution.
Original Microsoft figure showing the AutoJack end-to-end chain.
GitHub security advisory for CVE-2026-52870, affecting opt-in experimental tasks in mcp 1.23.0 through 1.27.1 and fixed in 1.27.2.
Maintainer advisory for the Windows-MCP HTTP transport vulnerability later assigned CVE-2026-48989.
Windows-MCP release notes describing the fix for GHSA-vrxg-gm77-7q5g.
Original Microsoft figure from the Semantic Kernel CVE-2026-26030 research article.
Microsoft's technical write-up of Semantic Kernel vulnerabilities, including the CVE-2026-26030 prompt-injection-to-RCE path and affected configuration.
GitHub-reviewed advisory for CVE-2026-26030, identifying affected Semantic Kernel Python versions and the patched release.
No shown records match these filters. Search the full library to continue.
Why this archive exists
DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.
We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.