When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion
VulnOn July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. Over roughly 17,600 actions, it reached dataset pipelines, production pods, cloud credentials, mesh VPN, and source control. The analysis maps the published incident to Qualys Container Runtime Security, Kubernetes Security Posture Management, and Cloud Detection and Response. These capabilities provide container-level eBPF telemetry, continuous CIS Benchmark and RBAC assessment, and cloud and SaaS API monitoring. This post explains which weaknesses Qualys TotalCloud could have surfaced accurately.
Read full story at Qualys Security Blog →