The kill chain here maps to Lockheed Martin 2011 end to end. Nothing in it needed a technique a red teamer has not run by hand on a Tuesday.
The part I keep thinking about is the reconstruction. Recovering 17,600 actions after the fact took decoded logs and a forensics effort. Most places running agents in production have neither, so their version of this ends at "something odd happened in July" and no timeline at all.
Wrote the whole thing up here: https://daniel-krol.com/an-ai-agent-intrusion-hugging-face/