Elektrine lite

← Feed

@buherator@infosec.place

Post #4185840

2026-07-29 06:41 UTC

HugginFace incident report: https://huggingface.co/blog/agent-intrusion-technical-timeline The report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s :) Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like an URL?). I feel sorry for blue teams not because they'll have to respond to more incidents but because they'll have to wade through reports like this...

Replies (3)

  • @ozu@infosec.exchange 2026-07-29 07:10

    @buherator@infosec.place what really bothers me is that – apart from a very few – no one pointed out how atrocious OpenAI's sandboxing was. Based on the reports it seems they used JFrog on the very same box to limit the model's access and roughly that's about it. On the top of it they haven't noticed their model was hacking another company for two days. That sounds more like OpenAI's absolute stupidity than their model's incredible capability. "Ah you know, our dog escaped containment not because we left the door wide open but because it's super intelligent."

    Open ##4186783

  • @buherator@infosec.place 2026-07-29 07:12

    This diagram is also bad, but at least it shows the high-level flows. Notice that "Third party code sandbox" is marked as "Compromised", while the post text explicitly states that "Modal’s infrastructure was not compromised in any way". Also, how do you even compromise a *sandbox*? WTF is Lateralize?!

    Open ##4186858

  • @buherator@infosec.place Yet another thing that lines up with the "fake incident for marketing purposes, both parties were in on it" conspiracy hypothesis. I'm tired, boss...

    Open ##4190384