HuggingFace incident report:
https://huggingface.co/blog/agent-intrusion-technical-timelineThe report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s :) Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like a URL?).
I feel sorry for blue teams not because they'll have to respond to more incidents but because they'll have to wade through reports like this...