This is a linkpost for https://openai.com/index/hugging-face-model-evaluation-security-incident/
Important section from the Huggingface incident report:
To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events. This allowed us to reconstruct the timeline, extract indicators of compromise, map the credentials touched, and separate genuine impact from decoy activity. Thanks to this approach, we were able to do in hours what would usually take days, and match the adversary's speed. [emph mine]
LW QT discussions: 1, 2