Thanks for being transparent with the security incident. I am curious to understand about the malicious dataset and agent driven attack.
Does malicious dataset has prompt injections that broken your AI agent or attacker built agent to run in your infra? Seems like a loose end in your platform engineering. tools should be restricted in servers that isn't required for the data processing operations. SELinux, Secomp, Apparmor, rbac etc. Moving laterally and compromising many nodes & clusters is not really expected when you have stronger infrastructure security.