Hugging Face disclosed an intrusion carried out end-to-end by an autonomous AI agent — and the incident exposed a troubling asymmetry: the attacker operated freely while defenders were blocked by safety guardrails on commercial AI models.
AI security incidents reconstructed from documented attack patterns to inform defence.
Hugging Face disclosed an intrusion carried out end-to-end by an autonomous AI agent — and the incident exposed a troubling asymmetry: the attacker operated freely while defenders were blocked by safety guardrails on commercial AI models.
Sygnia's investigation into a financially motivated cloud breach found a lone threat actor compressed what typically takes multiple operators weeks into 72 hours -- using AI-assisted tooling to chain credential theft, lateral movement, and extortion-ready disruption at a pace no human could sustain alone.
Meta's AI support chatbot had a confused deputy flaw allowing attackers to hijack Instagram accounts via recovery requests. 20,225 accounts compromised over 45 days.
A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, 2026, via stolen contributor PAT and malicious AI coding tool configs. Contained in 105 seconds.
An NHS trust confirmed adversarial perturbations applied to medical images caused systematic misclassification by its AI diagnostic system, resulting in incorrect preliminary diagnoses.