Lots of rule coverage and a rad interactive timeline by @jamesspi
hf-incident.threatsearch.io
When the attacker is an autonomous agent, outcome detections beat process tree trust.
OpenAI's eval models escaped a research sandbox during ExploitGym testing. The agent exploited a package-registry zero-day, reached the open internet, and hit Hugging Face's dataset processing pipeline.
Hugging Face reconstructed 17,000+ events from the intrusion. The TTPs were conventional: dataset pipeline RCE, credential harvest, lateral movement, self-migrating C2. The speed and alert volume were not.
We mapped MITRE ATT&CK and ATLAS stages to production Elastic Defend and SIEM rules you can enable today.
Full campaign analysis on the blog: go.es.io/4bg3sRK
Jul 30, 2026 · 2:58 PM UTC
1
6
354

