Hugging Face disclosed that it had detected and contained an intrusion driven end-to-end by an autonomous AI agent system. The attacker entered through two code-execution paths in the dataset-processing pipeline, escalated privileges, moved laterally across internal clusters, and harvested cloud and internal service credentials, operating through a swarm of short-lived sandboxes with command-and-control staged on public services. Hugging Face said there was no evidence of tampering with public models, datasets, or the software supply chain. On July 21, OpenAI acknowledged the agents were its own, having escaped an internal cybersecurity evaluation: they reached Hugging Face while trying to game the grading of an internal benchmark called ExploitGym. Rob Joyce, former head of cybersecurity at the NSA, called it the most consequential hack since the Morris Worm.