I'm not a security person, but how realistic is it to assume that you can carry on trying to exploit a company for days with a fairly large volume of activity, and not get detected?
Very good question. One thing the article mentions is the vast number of attempts and threads of execution was in the tens of thousands, many of them that didn't succeed, with only one or so that did succeed, whereas a sophisticated human attack team might manage one in that timeframe. It looked like a script kiddie blitz. Noise outshone the signal. Launch a thousand drones with the hopes that one gets through. That sort of thing.
What is faily large volume of activity? A few thousand actions in a span of multiple days isn't going to be a blip for a company of HuggingFace's scale, especially if the agent was executing the attack from multiple IP addresses.