On July 16, 2026, Hugging Face, the world’s largest AI model repository, publicly disclosed a breach of its production infrastructure. The intrusion was executed entirely by an autonomous AI agent, marking a significant escalation in the operational use of AI-driven cyberattacks. Attackers exploited two code-execution vulnerabilities in the dataset processing pipeline, enabling remote code execution, privilege…