Hugging Face-style agentic attack · Mitiga Labs

An autonomous agent took root on eleven nodes at Hugging Face.

We modeled an attack like it against ourselves.

We simulated the Hugging Face attack step by step and ran it against our own platform. Here's what we found, and what it would take to stop it in your environment.

What is a Hugging Face-style agentic attack?

A Hugging Face-style agentic attack is an intrusion run by an autonomous AI agent rather than a human operator. The agent gains code execution in one workload, then moves across spaces like Kubernetes, cloud, network, and source-control planes on machine identities with no malware or human login. The July 2026 Hugging Face incident is the public reference case.

What happenedThe 60-second version

An autonomous agent, running frontier models with its safety controls switched off, spent four and a half days inside Hugging Face's production infrastructure, with no malware and no human operator. It moved from one compromised pod to root on eleven nodes, read a secret holding 136 keys, and walked out with administrator access across multiple Kubernetes clusters.

4.5 Days

total intrusion

17,600

actions executed

11

nodes rooted

136

keys exposed

Modeled replay · Hugging Face intrusionSame attack,
two outcomes

Hugging Face's own security tooling caught the intrusion and correlated the signals into a coherent attack story. It just never raised the alarm loud enough, or fast enough, to matter.
‍
We took Hugging Face's published forensics and rebuilt the attack ourselves, then ran it against our own platform to see exactly where that timeline would change.

Get the Tabletop Exercise (.md)

52h

until the real victim contained it

< 1h

detected, composed and contained, modeled

Worker pod service account

Days 1–2

Code execution in one production worker pod; C2 set up on public paste and request-capture services.

What Mitiga sees

A worker reaching dead-drop services it has never contacted. Not yet an incident — recorded as evidence.

Day 3, 10:10 a.m. The Decision point

Reads its service-account token, probes the cluster API, enumerates RBAC, hits cloud metadata, authenticates to Kubernetes as the node.

What Mitiga sees

Three never-before-seen behaviors on one workload in minutes, with the earlier egress attached. Mitiga composes them into one Critical incident.

Day 3, 10:35–11 a.m.

Automated containment: the worker is quarantined, the service account and the node's cloud credentials revoked, the vulnerable path suspended.

What Mitiga sees

A worker reaching dead-drop services it has never contacted. Not yet an incident — recorded as evidence.

9h+

earlier than the attacker reached node root

In the modeled replay

Day 3, 7:53 p.m. → Day 5. Node root, the 11-node fleet, the 136-key secret, mesh pivot, cluster-admin, source-control write — none of it occurs.

× Node root

× 11-node fleet

× 136-key secret

× Cluster-admin

× Source-control write

Mitiga would not have stopped the agent from getting in. It would have stopped the agent from getting anywhere.

Critical

1 Incident

Kubernetes · AWS · Cloud metadata

Not more alerts. The right alert, escalated and acted on.

TRY IT OUTRun it against your own environment.

We turned the rebuild into a free, downloadable tabletop exercise any security team can run. It returns a one-page executive summary on whether your team would contain an attack like it in time.

Get the Tabletop Exercise (.md)   →

What decides the outcomeFour things decide whether anyone stops a Hugging Face-style agentic attack

Read backwards, an agentic intrusion comes down to four things that all have to go right. Miss one, and the other three stop mattering.

01 Arrive

The data has to arrive while it still matters

A chain that reaches cluster admin in hours doesn't wait for a daily log cycle. A data source that only delivers on a batch schedule hands you history, not evidence, and no model can make a log arrive sooner.

Near-real-time collection across every decisive source, measured in minutes, not a daily cycle. Top platform priority, in flight now.

02 Fire

Something has to fire on the identity that did the work

Every step in an agentic attack looks legitimate: a workload doing something it's technically allowed to do. Most detection was built to catch people, not workloads, using signals like impossible travel or a new device, and none of it fires when a service account does something it's never done before.

Coverage exists and some of it excluded service accounts by default. We found the gaps in this exercise and are closing them with continuous, machine-assisted verification of the detection library.

03 Compose

The signals have to compose in a window that matters

Correlation and triage are two different jobs. Hugging Face's stack did the first, assembling the signals into one coherent story, and failed at the second: deciding that story was critical enough to wake someone.

Our edge is strong here, and it is built as two tiers on purpose. Panoramic Awareness assembles the signals into one incident, Attack Decoding reconstructs the timeline, and AI Triage decides whether it is critical. We are sharpening that window further for identities that aren't people.

04 Act

Something has to act

A conclusion doesn't stop an attack. Hugging Face didn't fail because a human was too slow. They failed at the handoff, the step where a detection has to become a decision someone acts on.

We decide what's worth acting on, and how. Your response layer executes it. Keeping those two systems separate is a deliberate architecture choice.

No one is sitting at four out of four today, us included.

Go deeper on agentic attack containmentThree ways to go deeper

Read the full simulation

See the entire attack, modeled against Mitiga

A step-by-step replay of the Hugging Face intrusion: what the attacker did, what Mitiga would have seen, and where containment lands in the modeled replay.

Get the Insight Brief

Join the webcast

Inside the Hugging Face Agentic Attack: Detection, Response, and What You Should Do Next.

Ariel Parnes, Brandon Allen, and Brian Contos walk the attack step by step and score it against the four rows, on the record.

When
Tue, Oct 13 · 11:00 am CT
Speakers
Ariel Parnes · Brandon Allen · Brian Contos
Register

Run it yourself

Free , no form required

We turned the rebuild into a free, downloadable tabletop exercise any security team can run. It returns a one-page executive summary on whether your team would contain an attack like it in time.

Download the Exercise (.md)

FAQFrequently asked questions

What is in the Insight Brief?

+

The step-by-step model of the Hugging Face intrusion: each stage of the attack, the telemetry and detections it would demand, and where Mitiga would see it and where it would not. It is the long-form companion to the blog post, written for a CISO to forward.

Yes, and no form. It is a single markdown file. Fill in the environment profile with your team, paste the file into the AI model your organization already approves, and it returns a report: a one-page executive summary, then the full calculations as appendices. There's no readiness grade. It shows what the attack could reach, which paths your controls block, and whether you would contain it in time. Plan 60 to 90 minutes with SOC, cloud platform, identity, and someone who can authorize disrupting production.

No. It runs entirely inside your own model. Your answers, your report, and your gaps never reach us. The file is published under CC BY 4.0, so you can adapt it for internal use.

Security leaders and the engineers who would have to act on a Saturday morning: SOC and detection engineering, cloud and Kubernetes platform, and identity. Ariel Parnes, Brandon Allen, and Brian Contos walk the attack step by step and score it against the four rows.

We hold three of the four rows and are building the fourth, data latency, now. The full scorecard, with what each row means, is in the blog post.

Find out where you stand.

EDR protects your endpoints. Mitiga protects everything else.

Let them come.