To reconstruct the intrusion, Hugging Face analyzed more than 17,000 events. Interestingly, it eventually used GLM 5.2 within its own infrastructure because several commercial AI services blocked the real commands, exploits, and payloads contained in the logs.