Hugging Face 入侵复盘:4 个普通漏洞被 700 个智能体串联利用
Hugging Face 被入侵的细节复盘来了:4 个单看很普通的漏洞,被 700 个智能体串成一条攻击链,摸到 136 个生产密钥,做安全的都该看看。
这起入侵由约 700 个智能体在 4.5 天内执行 17,600 次操作完成,多数尝试是死路。最终串起 4 个单独看都不起眼的弱点:一个文件读取漏洞、一个模板注入、一个静态数据库密码和一批 service-account 令牌。四者组合后接触到 136 个生产环境密钥。如果按传统单一漏洞严重性评分排序,这几项都不会被优先处理。Cogent 的 Attack Path Analysis 借鉴这种思路,用智能体群先对自家环境做组合式攻击路径搜索。
The Hugging Face break-in came down to 4 unremarkable weaknesses and a lot of patience.
About 700 agents took 17,600 actions over 4.5 days, mostly dead ends, until those 4 lined up.
Cogent Attack Path Analysis runs that same kind of search against your own environment first, chaining weaknesses across systems and checking every hop against evidence from the tools you already run.
The 4 were a file-read bug, a template injection, a static database password and service-account tokens. Together they reached 136 production keys. Scored one at a time, none of them would have jumped the queue.
That's the gap @cogent_security is building for. Severity scores rate findings alone, but agent swarms win on combinations.
Hugging Face's engineers put it in one line: "Volume is what changes the defensive problem."