跳到正文
原文
rohanpaul_ai· @rohanpaul_ai · X·· 22 小时前AI 评分45

Hugging Face 遭入侵:4 个弱点被 700 个 agent 串联

AI 导读

Hugging Face 入侵事件由 4 个看似不起眼的弱点串联而成:约 700 个 agent 在 4.5 天内执行 17,600 次操作,最终通过文件读取 bug、模板注入、静态数据库密码和服务账号 token 组合触达 136 个生产密钥。

正文 · 原文

The Hugging Face break-in came down to 4 unremarkable weaknesses and a lot of patience.

About 700 agents took 17,600 actions over 4.5 days, mostly dead ends, until those 4 lined up.

Cogent Attack Path Analysis runs that same kind of search against your own environment first, chaining weaknesses across systems and checking every hop against evidence from the tools you already run.

The 4 were a file-read bug, a template injection, a static database password and service-account tokens. Together they reached 136 production keys. Scored one at a time, none of them would have jumped the queue.

That's the gap @cogent_security is building for. Severity scores rate findings alone, but agent swarms win on combinations.

Hugging Face's engineers put it in one line: "Volume is what changes the defensive problem."

来源:rohanpaul_ai · x.com