Register for the Workshop
Register to watch on-demand
Thank you for registering!
We've received your request and will get back to you soon.

If you do not hear from us in the next 48 hours, please check your spam folder!
Back to homepage
Webinar
On-demand Webinar
Webinar
On-demand Webinar
Episode 3

Movement isn’t visible (cross-plane lateral movement)

Join this 25-minute Attack Lab to examine real-world attacks—including the autonomous AI agent that compromised Hugging Face—and learn how to identify the behavioral patterns that reveal cross-plane lateral movement.

25 minutes
August 12, 2026
11 a.m. ET | CEST | SGT
Hosted in
English

Summary

Modern attacks rarely stay within one environment. They move across endpoints, identities, cloud infrastructure, SaaS applications, developer systems, and internal networks—creating fragments of activity that no single security tool can see or connect.

When movement crosses planes, visibility breaks down

In 2026, attackers—and now autonomous AI agents—can move across environments faster than most SOC tools can correlate their activity.

The Hugging Face compromise demonstrates the challenge. An autonomous AI agent entered through a malicious dataset, gained access to a processing worker, escalated to the node, harvested cloud and cluster credentials, and moved laterally across multiple internal clusters. No single security plane held the complete attack story.

In this Attack Lab, we will connect that incident with other real-world campaigns:

  • Hugging Face: An autonomous AI agent moved from untrusted content to worker, node, cloud credentials, and multiple clusters over a single weekend.
  • Sysdig AWS: An AI-driven intrusion used valid credentials to compromise a production cloud environment in approximately eight minutes.
  • Shai-Hulud: An npm supply-chain worm moved from a developer endpoint into CI/CD pipelines and downstream software packages.
  • Cl0p: Attackers exploited managed file-transfer platforms such as MOVEit and GoAnywhere to reach sensitive enterprise data.
  • UNC6395: Threat actors pivoted across interconnected SaaS platforms through Salesloft and Drift.

Each attack exploited the same underlying weakness: security controls captured individual events, but the movement between environments remained fragmented.

In this 25-minute lab, you will learn:

  • How attackers move across cloud, identity, SaaS, endpoints, developer infrastructure, and internal networks
  • How the Hugging Face compromise progressed from a malicious dataset to multiple internal clusters
  • Why anomalies alone are insufficient without correlation across security planes
  • Which behavioral patterns connect seemingly unrelated alerts into a single attack progression
  • Why SIEM, EDR, and native cloud tools often struggle to reconstruct cross-plane attacks
  • Three practical changes that can improve detection, investigation, and response

Who should attend

  • SOC analysts
  • Detection engineers
  • Threat hunters
  • Incident responders
  • Security operations leaders
  • Cloud and AI security practitioners

Stop Chasing Fragments. Start Seeing the Attack. Cross-plane attacks are not invisible. The evidence is distributed across tools, environments, and identities that were never designed to tell one story.

Join the lab to learn how to connect that evidence, recognize lateral movement sooner, and respond at the speed of an AI-driven attack.

Share

Speakers

Lucie Cardiet
Host
Cyberthreat Research Manager
Vectra AI

FAQs

About Vectra AI

Vectra AI is the leader in hybrid attack detection, investigation and response. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Vectra AI’s patented Attack Signal Intelligence empowers security teams to rapidly detect, prioritize, investigate and stop the most advanced hybrid cyber-attacks. With 35 patents in AI-driven detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI Platform and MXDR services to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai.