Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI intrusion patterns: are your identity controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12527
Topic starter  

TL;DR: The Hugging Face incident and Cato’s lab research show that autonomous AI systems can move from reconnaissance to domain administrator access in 40 minutes, while the real incident involved about 17,600 attacker actions over 4.5 days, according to Cato Networks. The governance gap is that identity controls still assume access is slow, reviewable, and human-paced, which autonomous execution breaks.

NHIMG editorial — based on content published by Cato Networks covering the Hugging Face incident: The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era

Questions worth separating out

Q: How should security teams authorize AI agents that can chain multiple actions?

A: Security teams should move beyond static allow or deny decisions and evaluate the agent’s purpose, context, and expected outcome at runtime.

Q: Why do existing access review processes fall short for autonomous AI?

A: Access reviews assume privileges persist long enough to be observed, recertified, and removed later.

Q: What breaks when AI agents are connected through personal accounts or shared credentials?

A: Shared or personal credentials break accountability, lifecycle control, and revocation.

Practitioner guidance

What's in the full article

Cato Networks' full article covers the operational detail this post intentionally leaves for the source:

  • A step-by-step reconstruction of how the Hugging Face incident moved from dataset processing into higher-level access and internal clusters.
  • The specific control failures that let credential exposure and movement through internal systems become part of the same attack path.
  • Cato’s lab findings on how a controlled agent reached Domain Administrator access in 40 minutes.
  • The response workflow details around analysing malicious payloads, command-and-control artefacts, and model refusal handling.

👉 Read Cato Networks' analysis of the Hugging Face incident and agentic AI risk →

Agentic AI intrusion patterns: are your identity controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12111
 

Agentic AI creates an assumption-collapse problem, not just a higher-volume NHI problem. Access review processes were designed for actors whose privilege persists long enough to be observed, certified, and revoked on a human cadence. That assumption fails when an autonomous system can acquire, combine, and use access across a single continuous run. The implication is that identity governance has to re-examine which controls depend on stable privilege windows.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • That confidence gap sits alongside another signal from the same research: 85% of organisations lack full visibility into third-party vendors connected via OAuth apps.

A question worth separating out:

Q: Who is accountable when an AI agent reaches privileged access too quickly for human review?

A: Accountability sits with the organisation that granted the access, not with the model itself. Governance should assign a business owner for each agent, define the approval chain for high-impact actions, and maintain audit records that show what access was granted, used, and withdrawn.

👉 Read our full editorial: Agentic AI can turn familiar intrusion patterns into machine-speed breaches



   
ReplyQuote
Share: