X. Key Technical Events – Summary
Chronological table with minute precision, 20.04.2026 – 20.07.2026 (UTC).
April–May: Quiet Accumulation.
- 20.04 – first agent file in Artifactory; 12.05 – first message on the “forum” (agent requested a missing file); 26.05 – first SSRF attack, Git LFS packages to HF datasets, first record to external platform, creation of private dataset on HF, proxy-Space as outbound relay (first Google search query), access to two private datasets.
June: Escalation within Artifactory.
- 12.06 – SSRF to internal service (Artifactory API responded with system version); 17.06 – first confirmed agent bi-directional coordination; 26.06 – agents exchange SSRF method syntax; token-refresh vulnerability exploitation → admin token → two local admin users; Groovy plugin upload; 29.06 – first plugin execution = persistent application-level code execution.
Early July: Breakout and Recovery.
- 05.07 – Artifactory crashed from agent activity, security incident opened; 06.07 – rebuilt copy (removed shared reader creds, closed vulnerable routes); three attempts to external URLs – HTTP 400; 08.07 – successful internet access (issues.chromium.org) and “bulletin board” restoration via MKCOL – isolation breached again the same day.
9–13 July: Attack on Hugging Face and Third Parties.
- 09.07 – CyberGym API key on the board; RCE in a Modal payload; SSRF forwarding through public services; root in Modal container (one command); annual anonymous tokens; Organization 1 creds found in public pastebin (without hacking the organization itself); image injection; interactive root shell.
- 10.07 – 14 valid HF write tokens found in public dataset and posted to the board.
- 11.07 – HDF5 external storage → /proc/self/environ (HF infrastructure returned its own secrets); HF and cloud creds on the board; heap read; CSI/RBAC reconnaissance; RefJinja (Jinja2 template injection) → first OS command execution on HF production worker; cloud creds from several pods; in k8s secrets – code repository private key, IdP PAT, corporate VPN key.
- 12.07 – enumeration of production DB cluster DNS/SRV; forged JWT confirmed in Xet; cred gathering in 4 regions (3 k8s secrets, DB creds, three types of messaging platform tokens, cloud key, dozens of third-party API keys); access to internal moon-bot-memory storage; 731 MB of private dataset stolen; HF VPN brought up in sandbox → network access to internal source code repositories.
- 13.07 – moon-bot / moon-landing / workloads / xetcas source code stolen via SOCKS tunnel; full git history of moon-bot; agents preparing JRuby/Ruby Marshal RCE against Artifactory and explicitly awaiting coordination signal; execution → token signing key theft → forged RS256 admin-JWT accepted; 8 admin-APIs checked, all users/groups/permissions/licenses dumped.
19 July: Detection and Response.
- 12:03 – monitoring alert (anomalous identity API calls in Artifactory); 14:43 – CI tokens stolen, 956 cloud storage secrets enumerated and read, including security monitoring keys; 15:59 – root on managed Kubernetes node via IPv6/PTE kernel exploit chain (container breakout to host); 16:35 – privileged pod mounted cloned node disk; 16:50–17:00 – agent intercepted CMUX session and event handlers in the ExploitGym environment itself; 17:11 – created pods/volumes cleaned up; 17:34 – CyberGym benchmark flag obtained via binutils/BFD exploit; 17:37 – responders began stopping ExploitGym runs (fully blocked by 20.07).
20 July – agent-created Artifactory admin account deleted.