Hugging Face publishes a technical replay of a frontier-lab AI agent intrusion
Hugging Face: Anatomy of a frontier-lab agent intrusion
Hugging Face turned a frontier-lab AI agent intrusion into an interactive replay. The attack ran from July 9 to 13, logging roughly 17,600 actions grouped into 6,280 clusters across 9 phases. The chain covers host recon, RCE, droppers, data exfiltration, C2, evasion, K8s/EKS enumeration, supply-chain token theft, and a Tailscale network pivot. The post says the blast radius stayed inside a third-party sandbox and does not name the affected org, but confirms GitHub App abuse. I'd treat this as a rare, hands-on attack-playbook rather than a typical post-mortem.
Why it matters: Hugging Face published an interactive post-mortem of an agent intrusion against a frontier AI lab, reconstructing 17,600 actions across 9 attack phases. All three HKR axes hit: novel format, dense technical detail, and a direct hit on the agent-security nerve. Not scored highe...