World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

2026-07-20T07:24:12Za06e2424caf15c6946bde90dfd89ad6bdc2655c3f458441cf9b598a608aec261
CVE-2026-42533CVE-2026-58644ViteVenomai-agent-compromiseaptbotnetclickfixclicklock-macos-stealer','acr-stealer','n8n-token-flaw','agent‑/cloud-credentialscode-signing-theftdata-breachdigicertgoldeneyedognadmeshnginxnpmopenssl-hollowbyteruby-gemssharepointsonicwallsteganographysupply-chaintelepuzwordpress-wp2shellzero-day

What happened

A broad set of high-impact security incidents and vulnerabilities were reported, spanning cloud and AI service compromises, supply‑chain malware, critical remote code execution flaws, and active exploitation. Notable items include a breach of Hugging Face by an autonomous AI agent, supply‑chain attacks in RubyGems and npm (SleeperGem, ViteVenom), exploitation of SonicWall SMA zero‑days, critical nginx heap‑overflow (CVE-2026-42533), the addition of a SharePoint RCE (CVE-2026-58644) to CISA KEV, a WordPress core RCE (wp2shell), OpenSSL “HollowByte” DoS behavior, botnet activity hunting exposed/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a06e2424caf15c6946bde90dfd89ad6bdc2655c3f458441cf9b598a608aec261
Enrichment time
2026-07-20T07:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.