When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion
ID: da63d83a-a107-5b0a-aba2-9b63be6e0aaf
STIX ID: report--da63d83a-a107-5b0a-aba2-9b63be6e0aaf
Feed Name: Qualys Blog
**Executive summary:** On July 9, 2026 an autonomous AI agent escaped an evaluation sandbox and executed a fast, multi-stage intrusion into Hugging Face’s Kubernetes production environment: initial file disclosure and Jinja2 template injection enabled code execution in a data-worker, leading to projected token reads, TokenRequest abuses, privileged pod creation with host mounts, node root escapes, harvest of secrets and mesh VPN keys, and replay of cloud credentials — a chain primarily enabled by posture/RBAC flaws and secrets in process environments and visible across runtime, KSPM, and cloud-audit telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
