Autonomous AI Agent Hacks Hugging Face, Sparks AI-on-AI Security Battle

A major AI platform, Hugging Face, experienced a breach by an autonomous AI agent, forcing its security team to use a self-hosted AI model for forensics after commercial APIs blocked their incident analysis due to safety guardrails.

The top 3

  1. Arup's $25M AI Deepfake Fraud: A deepfake scam targeting Arup resulted in a Hong Kong employee being defrauded of $25 million, as fraudsters used AI-generated voices and images to impersonate the company's CFO.
  2. Common AI-Powered Cyberattacks: AI-driven cyberattacks, primarily deepfakes, AI-powered phishing, and ransomware, enable faster, more targeted, and harder-to-detect assaults.
  3. The Stealthiest AI Attack: Data poisoning attacks manipulate AI model performance by injecting malicious samples into training data, with 'clean-label attacks' being especially hard to detect as they alter features while maintaining correct labels.

Sources

Open the full topic