This week’s news on the OpenAI/Hugging Face security incident marks a pivotal moment in cybersecurity: it’s the first time that a fully autonomous attack chain—without a human in the loop for command-and-control decision-making—has been observed.
We’ve been observing this trend for at least the last year: LLMs are increasingly capable of running advanced attack chains autonomously, at a speed that most security organizations are not ready for.
It also highlights an under-discussed factor: while the focus for most organizations in responding to the new requirements presented by frontier AI threats is often on software vulnerabilities and “faster patching,” models are equally capable at exploiting compromised credentials to achieve their goal via lateral movement and privilege escalation. That’s why identity is becoming the critical control plane for stopping autonomous attacks.
The implication for defenders is clear: preventing these attacks requires controls that operate at machine speed. Software security remains essential, but it must be complemented by inline, runtime identity controls that can interrupt attack paths as they unfold. This is not about replacing existing investments—it’s about adding a defense-in-depth layer that remains effective when attackers inevitably gain an initial foothold.
At Silverfort, we’ve seen this firsthand in our work with some of the world’s largest organizations, including customers participating in Project Glasswing and Frontier AI Red Teaming, which we’ve previously written about.
THREAT INTELLIGENCE REPORT
The Mythos Field Report
Discover what actually stops AI-powered attacks.
This incident reinforces the fact that the bar for defenders has raised—not just for software, but for identity, too.
Across cybersecurity, fighting machine-speed threats with human-speed controls is insufficient to protect our businesses. Identity is no exception: runtime, inline controls are the only way to build resilience and effectiveness in countering AI-powered attacks targeting identity.
What happened in the Hugging Face incident?
Following Hugging Face’s incident notification, OpenAI confirmed that the incident originated from an internal model-testing exercise—but it was nevertheless a real attack. An autonomous agent escaped its intended sandbox, reached the public internet, and independently chose to attack Hugging Face’s infrastructure in pursuit of its objective.
The key takeaway is not whether this began as a controlled evaluation—it’s that the agent autonomously transitioned into offensive operations outside its intended environment. Once it escaped containment, it independently selected a target, planned and executed an attack chain, adapted its behavior, and persisted toward its objective. That is the real milestone. Frontier AI is no longer simply a capability that adversaries can leverage. Increasingly, those models are capable of becoming the operator itself.
Using 5.6 Sol and an unreleased model version to test cyber capabilities (ExploitGym)—with guardrails removed—the model identified that solutions to the ExploitGym exercise may lie in Hugging Face’s infrastructure.
By chaining novel vulnerabilities and credential compromise, it broke out of its sandbox, then OpenAI’s environment to the internet—before establishing a foothold in Hugging Face’s production environment using a remote code execution path and exploiting stolen credentials to achieve its goal. Command & control was delivered via public services, self-migrating to avoid containment action.
The Hugging Face team contained the incident, supported by an open-source LLM (GLM 5.2), used to reconstruct the attack chain timeline across 17,000 events, including exposed credentials. An open-source product was used, given the guardrails in place for commercial products blocked analysis—highlighting the asymmetry of unconstrained/open-weight model capabilities and usage-constrained defender tools.
How does this agent incident fit into the broader trend of AI-powered attacks?
This is the continuation of a trend of increasing capability and self-direction.
The UK’s AI Security Institute’s testing shows continual advancement against benchmark tests:

These capabilities are now being utilized by attackers at increasing velocity to exploit identity weaknesses:

- Anthropic report – Nov 2025 – APT use of LLMs, human-directed with 80-90% independence.
- Anthropic – June 2026 – AI being used for higher value-add late-stage attack support; for example, lateral movement and credential discovery; increasing autonomy.
- Sysdig/JadePuffer – 1 July 2026 – First case of LLM-driven ransomware; initial access via vulnerability followed by immediate credential sweep, targeting LLM provider API keys, cloud provider credentials and database credentials.
- Sygnia – 8 July 2026 – Enterprise cloud environment compromise in 72 hours; AI-assisted. Exploited exposed secrets and weak identity controls with multiple attack paths running in parallel.
- Hugging Face – 20 July 2026 – First fully autonomous attack chain.
What can we learn from this security incident?
Beyond the obvious—that frontier AI models are highly capable of creating & now operating end-to-end novel attack chains at machine speed—this highlights the importance of Identity Security in a balanced, resilient approach to AI-powered threats.
Traditional identity investments are not enough
For identity, this means that compliance- or operations-led programs are at risk.
Fighting machine-speed threats that are multi-threaded, intelligent and flexible in execution of novel attack paths requires controls that also operate at the same speed.
Anything else—IGA programs that operate in admin-time, or PAM programs targeting a narrow subset of privileged human identities—are too slow and static, or too limited to counter this new threat.
Build resilience with identity controls
Some have suggested in response to these incidents that air-gapped environments are the only ones that will be safe; this is not a practical reality for most cloud-enabled businesses.
Our take is different: this reinforces the need for identity and access runtime controls to mitigate the risk of the identity debt in your company and prevent threats: unprotected privileged identities with standing access (especially non-human), over-privilege, insecure storage of credentials, stale accounts, and legacy authentication protocols. The objective is defense-in-depth: ensuring that if one layer is bypassed, identity controls can still prevent attackers from progressing.
There simply isn’t the time to take on the remediation programs to remove standing risk; the Hugging Face incident highlights the real threat of unconstrained open-source and open-weight close-to-frontier models in the hands of attackers in the coming weeks and months.
These are proven to interrupt the development and progression of the attack chains that frontier model attacks operate through, reinforcing and extending your current posture established by IGA and PAM, by bringing machine-speed risk control to your environment. Identity resilience to frontier threats is the outcome.
Final thoughts on the new AI-powered attack model
The Hugging Face incident is unlikely to be remembered because it targeted a particular organization. It will be remembered because it demonstrated a new operating model for attackers: a fully autonomous attack chain—without a human in the loop.
Organizations cannot respond to this shift with human-speed processes alone. Resilience will come from defense-in-depth—combining strong vulnerability management with inline, runtime identity controls that can stop attack chains as they unfold.
The organizations that adapt their defenses to operate at machine speed will be best positioned to withstand the next generation of AI-powered attacks.
GUIDE
Stop AI-powered attacks
Get your readiness guide to learn why identity is the primary battlefield and strategies to get your organization prepared.


