Hugging Face 遭约 700 个 AI 智能体在 4.5 天内发起 17,600 次操作入侵,最终靠 4 个不起眼的弱点组合拿到 136 个生产密钥:文件读取漏洞、模板注入、静态数据库密码和服务账号 token。Cogent Attack Path Analysis 据此推出防御侧产品,在自有环境中串联跨系统弱点并逐跳核验,因为严重性评分只看单项发现,而智能体集群靠组合取胜。
The Hugging Face break-in came down to 4 unremarkable weaknesses and a lot of patience.
About 700 agents took 17,600 actions over 4.5 days, mostly dead ends, until those 4 lined up.
Cogent Attack Path Analysis runs that same kind of search against your own environment first, chaining weaknesses across systems and checking every hop against evidence from the tools you already run.
The 4 were a file-read bug, a template injection, a static database password and service-account tokens. Together they reached 136 production keys. Scored one at a time, none of them would have jumped the queue.
That's the gap @cogent_security is building for. Severity scores rate findings alone, but agent swarms win on combinations.
Hugging Face's engineers put it in one line: "Volume is what changes the defensive problem."
Most of AI Twitter read the OpenAI breach of Hugging Face as an alignment story. It was also a preview of what every hacker will be able to do in a few months. In July, a swarm of 700 AI agents broke into Hugging Face and fired off more than 17,000 actions, gaining admin control of multiple internal clusters. Swarms like this will shred cyber defenses built for human attackers at every company, hospital, government, and power plant. Today we're launching the defensive counterpart. Cogent Attack Path Analysis finds the routes an agent swarm would take into your company, so you can close them first.在 X 查看被引用的帖子
来源:Rohan Paul · x.com