About this talk
Presented by: Ariel Parnes, Co-Founder & COO · Brandon Allen, Head of Cyber Defense · Brian Contos, Field CISO
In July 2026, an autonomous AI agent spent four and a half days inside Hugging Face's production infrastructure using stolen machine identities. It went from a file-parsing bug to node root, a cluster secret full of keys, the corporate mesh, cluster admin across clusters, and a pull request against CI. Most of its ~17,000 actions failed, and the chain that worked looked routine in every log it touched. It used no malware, no phished employee, and no human account.
Nothing in that chain leaned on an endpoint. EDR protects the endpoint. Mitiga protects everything else, across cloud, SaaS, identity, third-party services, and AI.
So we modeled the attack using Hugging Face's published forensics against our platform and scored it on four rows.
- Latency. Does the data arrive in minutes or on a daily batch cycle?
- Detection. Does anything fire when a service account does something it has never done?
- Composition. Do those signals combine into a single incident quickly enough to page someone?
- Response. Does something act on the incident?
You'll leave with...
- Each step of the attack as the logs recorded it
- Our four-row scorecard, which marks what we tested and what we modeled
- How Panoramic Awareness and Attack Decoding turn entries in separate logs into one timeline, and where Attack Containment stops it
- The Agent Intrusion Tabletop and what the report returns