Anatomy of an autonomous intrusion
Could you have caught this?
Watch the OpenAI-Hugging Face incident play out as it happened, and see what opportunities existed to catch it.
The intrusion, at evidence speed
Follow the chain from containment escape to production execution, credential expansion and sustained staging. The replay compresses only dead time; every mark retains its true UTC instant and opens into the evidence behind it.
Escape from the operator's evaluation sandbox via a package-proxy zero-day
Quiet stretches longer than 30 minutes are cut so the replay stays watchable. Each on the axis marks a cut; the clock always reads the true UTC instant.
What the behavior leaves behind
Objects model durable behavior, not disposable indicators. “Conditional” is the important answer: the signal exists only when a specific audit tier, inventory or correlation history was already in place. Lab badges show what was actually exercised—not what is merely plausible.
ScopeThe pack models victim-side control planes. The rooted third-party launchpad remains visible because removing it would falsify the sequence, but it does not inflate coverage.
ValidationTwo strategies held under test, fifteen held in part, and 55 remain untested hypotheses. Partial results are presented as boundaries, never as confirmation.
Blind spotsFive objects conclude “no.” These are not missing rules; they identify behavior for which the available system simply did not create a distinguishing record.