- Cybersecurity Docket
- Posts
- Hugging Face Warns Autonomous AI Agent Hacked Its Network
Hugging Face Warns Autonomous AI Agent Hacked Its Network
Plus, U.S. government weighing FINRA-like watchdog to vet top AI models.

Good morning! Here’s what’s up.

People
Dirk Spacek has joined Swiss law firm Wenger Plattner as partner in the firm’s IP/IT and data protection practice group, as of July 1. Spacek advises Swiss and international companies on complex issues at the intersection of technology, law and business, particularly regarding data-driven business models and regulatory matters. Previously, he was a partner and co-practice head of the IT/IP team at CMS Switzerland.

Clips ✂️
Hugging Face warns an autonomous AI agent hacked its network
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Hugging Face is an open-source AI and machine learning platform that provides access to over 45,000 models from leading AI providers and is used by more than 50,000 organizations.
The company is still investigating whether partner or customer data was affected and said it would contact any affected parties directly. Hugging Face said it has found no evidence of tampering with public-facing models, datasets, or Spaces to date, and that its software supply chain has been "verified clean."
The intrusion began in Hugging Face's data-processing pipeline, with the attackers using a malicious dataset to exploit two code-execution vulnerabilities and run code on a processing worker. This allowed them to steal cloud and cluster credentials and move laterally across several internal clusters.
US Considers Creating Finra-Like Watchdog to Vet Top AI Models
The Trump administration is considering plans for an independent regulator to vet the safety of artificial intelligence models with industry input, after Silicon Valley leaders complained about the ad-hoc nature of recent U.S. moves to slow the release of cutting-edge AI systems.
Treasury Secretary Scott Bessent helped develop the proposal, which would create an independent regulatory agency for AI that would report to the Securities and Exchange Commission, similar to the Financial Industry Regulatory Authority, according to people familiar with the matter. The plan is now being reviewed by White House Chief of Staff Susie Wiles, said the people, who spoke on condition of anonymity because it has not been made public.
Such an approach would offer more certainty for leading AI labs like Anthropic PBC, which last month was hit with U.S. export controls that led it to temporarily disable its Fable 5 and Mythos 5 models, and OpenAI, which made significant changes at the government’s request before releasing its latest Sol model. Both companies objected to the government’s moves, calling them excessive relative to the safety issues identified by U.S. officials.
Abbott investigates two separate cyber incidents, says no operations affected
Abbott Laboratories is investigating two cyber incidents involving unauthorized access to some internal systems at its cancer diagnostics business and its LabCentral portal, the company said on Friday, adding that its operations were not affected.
No other businesses, sites or systems were impacted by the incident at the cancer diagnostics unit, the medical device maker said, adding that legacy Exact Sciences systems were separate from Abbott's systems.
A hacker also allegedly gained access to the LabCentral portal, an externally facing third-party-hosted portal used by Abbott's core laboratory diagnostics business. But there had been no impact to its businesses or customers and no known exposure of sensitive customer or business information, the company said.
Cyberattacks have increasingly targeted healthcare companies, with recent incidents affecting firms such as Clover Health Investments, Stryker, Medtronic, Novo Nordisk, and West Pharmaceutical Services.
Clover Health says employee accounts accessed in cyber incident
Clover Health Investments said in a regulatory filing on Friday that it detected unusual login activity on some of its information systems on July 4 and later found a hacker had gained access to three employee accounts through social engineering.
The health insurer said the affected accounts belonged to non-managerial health plan employees who handled member visit scheduling and broker-facing sales work.
These accounts could access some personal and protected health information, according to the company, but not corporate financial or claims systems.
Clover began an investigation with external cybersecurity experts, took steps to contain the activity and notified law enforcement, it said.
The investigation is ongoing and the company is still reviewing what information may have been accessed or taken. Clover believes its response curbed and ended the unauthorized access.
Aviation cybersecurity has key shortfalls, watchdog warns Congress
The Transportation Security Administration and Federal Aviation Administration have cybersecurity gaps sending stakeholders mixed signals and falling short of federal standards, according to a new congressional watchdog report.
The TSA’s cybersecurity plan, the Cybersecurity Roadmap, is essentially frozen at 2018 and no longer aligned with the Department of Homeland Security’s latest Cybersecurity Strategy, according to a Thursday report from the Government Accountability Office.
The agency was to update its roadmaps, including that involving cybersecurity, between 2018 and 2026, but it has yet to do so.
While the FAA has clearly defined cybersecurity roles and responsibilities across its entities, the TSA does not specify which offices are responsible for what.
This has caused confusion among aviation stakeholders, including airlines, avionics manufacturers and industry groups, about what falls under TSA versus FAA.
An airline’s representatives told GAO that “they felt that the agency lacked the resources, authority and expertise to properly regulate cybersecurity,” according to the report.
Why Digital Supply Chain Attacks Are Emerging as the Biggest Cybersecurity Threat for Businesses
As businesses strengthen their internal cybersecurity defenses, cybercriminals are increasingly shifting their focus to a more vulnerable target—the digital supply chain. Rather than attempting to breach organizations directly, attackers are exploiting trusted third-party vendors, software providers, cloud services, and open-source components that already have authorized access to critical systems and sensitive data.
Traditional cybersecurity strategies have long emphasized protecting internal networks through firewalls, encryption, access controls, and employee awareness programs. However, the growing reliance on interconnected digital ecosystems means these measures alone are no longer enough. Organizations now depend on a broad network of suppliers and technology partners, creating multiple entry points that hackers can exploit.
