Hugging Face-style agentic attack · Mitiga Labs
We modeled an attack like it against ourselves.
We simulated the Hugging Face attack step by step and ran it against our own platform. Here's what we found, and what it would take to stop it in your environment.

A Hugging Face-style agentic attack is an intrusion run by an autonomous AI agent rather than a human operator. The agent gains code execution in one workload, then moves across spaces like Kubernetes, cloud, network, and source-control planes on machine identities with no malware or human login. The July 2026 Hugging Face incident is the public reference case.
An autonomous agent, running frontier models with its safety controls switched off, spent four and a half days inside Hugging Face's production infrastructure, with no malware and no human operator. It moved from one compromised pod to root on eleven nodes, read a secret holding 136 keys, and walked out with administrator access across multiple Kubernetes clusters.
total intrusion
actions executed
nodes rooted
keys exposed
Hugging Face's own security tooling caught the intrusion and correlated the signals into a coherent attack story. It just never raised the alarm loud enough, or fast enough, to matter.
We took Hugging Face's published forensics and rebuilt the attack ourselves, then ran it against our own platform to see exactly where that timeline would change.
until the real victim contained it
detected, composed and contained, modeled
Code execution in one production worker pod; C2 set up on public paste and request-capture services.
What Mitiga sees
A worker reaching dead-drop services it has never contacted. Not yet an incident — recorded as evidence.
Reads its service-account token, probes the cluster API, enumerates RBAC, hits cloud metadata, authenticates to Kubernetes as the node.
What Mitiga sees
Three never-before-seen behaviors on one workload in minutes, with the earlier egress attached. Mitiga composes them into one Critical incident.
Automated containment: the worker is quarantined, the service account and the node's cloud credentials revoked, the vulnerable path suspended.
What Mitiga sees
A worker reaching dead-drop services it has never contacted. Not yet an incident — recorded as evidence.
9h+
earlier than the attacker reached node root
In the modeled replay
Day 3, 7:53 p.m. → Day 5. Node root, the 11-node fleet, the 136-key secret, mesh pivot, cluster-admin, source-control write — none of it occurs.
× Node root
× 11-node fleet
× 136-key secret
× Cluster-admin
× Source-control write
Mitiga would not have stopped the agent from getting in. It would have stopped the agent from getting anywhere.
Critical
1 Incident
Kubernetes · AWS · Cloud metadata
Not more alerts. The right alert, escalated and acted on.
We turned the rebuild into a free, downloadable tabletop exercise any security team can run. It returns a one-page executive summary on whether your team would contain an attack like it in time.
Get the Tabletop Exercise (.md) →Read backwards, an agentic intrusion comes down to four things that all have to go right. Miss one, and the other three stop mattering.
01 Arrive
A chain that reaches cluster admin in hours doesn't wait for a daily log cycle. A data source that only delivers on a batch schedule hands you history, not evidence, and no model can make a log arrive sooner.
Near-real-time collection across every decisive source, measured in minutes, not a daily cycle. Top platform priority, in flight now.
02 Fire
Every step in an agentic attack looks legitimate: a workload doing something it's technically allowed to do. Most detection was built to catch people, not workloads, using signals like impossible travel or a new device, and none of it fires when a service account does something it's never done before.
Coverage exists and some of it excluded service accounts by default. We found the gaps in this exercise and are closing them with continuous, machine-assisted verification of the detection library.
03 Compose
Correlation and triage are two different jobs. Hugging Face's stack did the first, assembling the signals into one coherent story, and failed at the second: deciding that story was critical enough to wake someone.
Our edge is strong here, and it is built as two tiers on purpose. Panoramic Awareness assembles the signals into one incident, Attack Decoding reconstructs the timeline, and AI Triage decides whether it is critical. We are sharpening that window further for identities that aren't people.
04 Act
A conclusion doesn't stop an attack. Hugging Face didn't fail because a human was too slow. They failed at the handoff, the step where a detection has to become a decision someone acts on.
We decide what's worth acting on, and how. Your response layer executes it. Keeping those two systems separate is a deliberate architecture choice.
No one is sitting at four out of four today, us included.
Read the full simulation
A step-by-step replay of the Hugging Face intrusion: what the attacker did, what Mitiga would have seen, and where containment lands in the modeled replay.
Join the webcast
Ariel Parnes, Brandon Allen, and Brian Contos walk the attack step by step and score it against the four rows, on the record.
Run it yourself
We turned the rebuild into a free, downloadable tabletop exercise any security team can run. It returns a one-page executive summary on whether your team would contain an attack like it in time.
The step-by-step model of the Hugging Face intrusion: each stage of the attack, the telemetry and detections it would demand, and where Mitiga would see it and where it would not. It is the long-form companion to the blog post, written for a CISO to forward.
Yes, and no form. It is a single markdown file. Fill in the environment profile with your team, paste the file into the AI model your organization already approves, and it returns a report: a one-page executive summary, then the full calculations as appendices. There's no readiness grade. It shows what the attack could reach, which paths your controls block, and whether you would contain it in time. Plan 60 to 90 minutes with SOC, cloud platform, identity, and someone who can authorize disrupting production.
No. It runs entirely inside your own model. Your answers, your report, and your gaps never reach us. The file is published under CC BY 4.0, so you can adapt it for internal use.
Security leaders and the engineers who would have to act on a Saturday morning: SOC and detection engineering, cloud and Kubernetes platform, and identity. Ariel Parnes, Brandon Allen, and Brian Contos walk the attack step by step and score it against the four rows.
We hold three of the four rows and are building the fourth, data latency, now. The full scorecard, with what each row means, is in the blog post.
EDR protects your endpoints. Mitiga protects everything else.
Let them come.
