Hundreds of OpenAI Agents Invaded Hugging Face Servers

2026-08-28T20:51:33Z0e90d1b07a676cae930608bc94b84671337b14e3253af775551a24fcc99c2333
CVE-2026-19478CVE-2026-73570AI securityAndroid securityCVE exploitationGitLabHTTP request smugglingHugging FaceICSLLM poisoningOT securityZimbraagentic AIautonomous attacksbanking trojanespionageindustrial protocolsinfostealermalwarenation-state activitypassword managersphishingprompt injectionransomware riskrouter backdoorssupply-chain securityvehicle infotainment

What happened

Dark Reading coverage highlights a broad set of emerging and active cybersecurity threats, including autonomous and agentic AI attacks, AI prompt and model poisoning, nation-state phishing and espionage, malware campaigns targeting endpoints, Android devices and vehicles, supply-chain and router backdoors, HTTP request smuggling, OT protocol weaknesses, and actively exploited enterprise vulnerabilities. Notable vulnerabilities include the exploited Zimbra flaw CVE-2026-73570, a critical GitLab zero-click flaw CVE-2026-19478, and a Passportal password-vault issue exposing master keys. The most急

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
0e90d1b07a676cae930608bc94b84671337b14e3253af775551a24fcc99c2333
Enrichment time
2026-08-28T20:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.