
Yup.
The attack was initially surfaced through AI-assisted detection. Our anomaly-detection pipeline uses LLM-based triage over security telemetry to separate real signals from the daily noise, and it was the correlation of those signals that flagged the compromise.
That’s in the article from HuggingFace. Not saying you’re right, but if you are, that’s what you were looking for.

Why can they spend money now, but make it so on paper it’s as if they spent it next quarter?