The figure is a forensic artifact rather than a severity score: more than 17,000 recorded events is the size of the log Hugging Face had to read to separate genuine impact from decoy activity in the intrusion it disclosed for July 2026 [2]. Volume at that scale is what turned model access into an operational dependency. The company says the campaign was run by an autonomous agent framework firing many thousands of actions from a swarm of short-lived sandboxes, with command and control that migrated itself across public services [3]. Both halves of the response were model work too: LLM triage over security telemetry correlated the signals that flagged the compromise [8], and analysis agents rebuilt the timeline and mapped the credentials touched in hours instead of days [10].
The part worth filing is why it ran on GLM-5.2. Submitting real attack commands, exploit payloads and C2 artifacts to commercial frontier APIs got the requests blocked by provider guardrails which, in Hugging Face's account, cannot distinguish an incident responder from an attacker [5]. The responders switched to an open-weight model on their own infrastructure, which also kept attacker data and the credentials it referenced inside the environment [6]. Hugging Face says it does not know what model the attacker's agents used, jailbroken hosted or unrestricted open weights, and notes the intruder was bound by no usage policy while its own forensic work was [7].
Set against that one documented case, the aggregate picture is thinner than it reads. METR reports vulnerability disclosure sharply up in 2026 on 2025 across cURL, OpenSSL, Firefox, Microsoft, the US NVD and OSV [12], with AI-marked credits carrying most of the extra volume on cURL and OpenSSL but only a small share elsewhere [13]. The databases of exploited vulnerabilities, CISA and Vulncheck KEV, grew significantly slower [14]. METR also says its own collection was done by agents and covers public discoveries only [16]. Offense has a detailed log and a rising curve. Defense has one company's weekend, with the assessment of whether partner or customer data was affected still open [9].