Hugging Face's AI guardrails locked out its own defenders
A weekend AI-agent attack ran 17,000+ actions; commercial models refused to help investigate, so HF fell back to open weights. Plus Claude Code 2.1.216.

Copy markdown
Guardrails locked out the defenders
An autonomous agent ran 17,000+ actions against Hugging Face over a weekend, but when responders fed the captured exploit commands to commercial frontier models, the models refused - their guardrails can't tell an incident responder from an attacker. HF ran the open-weight GLM 5.2 on its own infrastructure instead. The takeaway for your security work: keep a capable open model vetted and ready to run locally before you need it.
Rotate your Hugging Face tokens now
The breach started with a malicious dataset that chained a remote-code loader and a config template injection to harvest service, cloud, and cluster credentials. Hugging Face is telling every user to rotate access tokens and review recent account activity - there's no evidence public models, datasets, or Spaces were tampered with, but do the rotation anyway.
Claude Code 2.1.216 ships
The July 20 build adds a sandbox.filesystem.disabled setting so you can skip filesystem isolation while keeping network-egress control, and it finally stops auto mode from denying commands after a mid-session OAuth refresh throws HTTP 401. Cloud sessions now re-run interrupted turns on resume, and the quadratic slowdown that stalled long sessions is gone.
Blomkamp ships a fully-AI short
District 9 director Neill Blomkamp released Nightborne, a 13-minute sci-fi horror short generated entirely with Seedance 2.0, using the licensed faces and voices of 32 real people plus human concept art. Critics panned it, but text-to-video is now good enough for a name director to ship a narrative test - and he's founding Barley Studios to make a feature the same way.