Daylight Security published a report by Brian Donohue and Oren Biderman on the Hugging Face breach, leaked credentials, a template injection bug, and post-exploitation activities.
Public source
Publisher name
Public post
Really great work from Brian Donohue & Oren Biderman, Ph. D. Our take on the Hugging Face breach - leaked creds, a template injection bug, and classic post-exploitation…
Company
Daylight Security
Leading the Managed Agentic Security Services Revolution
- Industry
- Computer and Network Security
- Location
- New York, US
- Company size
- 51–200 employees
About Daylight Security
Managed security services, rebuilt for SecOps. Traditional MDR can’t keep up with modern threats. AI SOC tools help with investigations, but still require a SOC team. Daylight introduces Managed Agentic Security Services (MASS), a new model where AI agents and security experts run your security operations together.
See moreLatest activity
Latest activity from Daylight Security
8 signals
Presence & Recognition
Daylight Security Security Engineering Team Leaders Kyle Henson and Aaron Zhongyuan are taking the stage to share what they've learned putting AI to work in incident response.
Presence & Recognition
Daylight Security received a 5-star rating from Gartner Peer Insights for its AI-native platform and security experts with 10+ years of experience in IR and threat hunting backgrounds.
People
Daylight Security is hiring for an All-Star SDR role with remote work, competitive salary, equity, travel opportunities, and a fast-paced startup environment.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Cyera
Cyera published a research paper looking at the OpenAI/Hugging Face incident, detailing an AI agent that reached cluster-admin access in under 13 hours.
Research & Knowledge
HAWK Network Defense
HAWK Network Defense published findings from honeypot telemetry documenting attackers actively exploiting MCP gateways, sending blind prompt injections to exposed agents, deploying cryptominers through AI-management interfaces, and extracting model credentials directly from process memory.
Research & Knowledge
Synack
Synack published Tim Nordvedt's analysis breaking down how frontier AI models compress the window between vulnerability and exploit.
Research & Knowledge
DOT Security
DOT Security published an edition of The DOT Report featuring AI-powered hacking tools now for sale on underground forums.
Research & Knowledge
VulnCheck