Supply chain security

Blog posts tagged “supply chain security”


Inside the Hugging Face Breach an AI Agent Ran Start to Finish

Hugging Face OpenAI AI security

Hugging Face disclosed that an autonomous AI agent, not a human operator, chained two dataset-pipeline bugs, harvested credentials, and moved laterally through its production clusters. Days later, OpenAI confirmed the agent was its own pre-release model, loose from an internal cybersecurity benchmark. Here's how it worked and what it means for anyone running ML infrastructure.

Agentjacking: How a Fake Sentry Bug Report Hijacks Your AI Coding Agent

AI security agentjacking MCP security

A new attack called agentjacking uses public Sentry DSNs and MCP to inject malicious instructions into Claude Code, Cursor, and Codex - then exfiltrates your AWS keys, GitHub tokens, and git credentials. 85% success rate, 2,388 orgs exposed, zero authentication needed.