Hugging Face said an AI agent was used to attack its infrastructure, according to The Decoder. The incident is notable because it shifts the security discussion from AI-written phishing or malware toward agents that can carry out multi-step operations.
The company also said it used AI in its defensive response. That points to a likely pattern for security teams: attackers and defenders will both use automation to scan, reason, and act faster than humans can manage manually.
The important limitation is that agentic attacks do not make traditional security basics obsolete. Identity controls, logging, rate limits, and incident response still matter. What changes is the tempo. If autonomous tools can chain actions quickly, organizations need defenses that can detect and interrupt those chains before a small weakness becomes a broader compromise.