Hugging Face Data Breach
17 hours ago
- Hugging Face disclosed a hack compromising internal datasets and service credentials.
- Attackers exploited a vulnerability via a malicious dataset to escalate permissions and access internal systems.
- Stolen credentials have been revoked and rotated; users advised to review their accounts.
- The vulnerability has been fixed, highlighting platform abuse challenges.
- Hugging Face attributed the breach to an external AI agent executing numerous actions.
- Anomaly detection and an internal AI model analyzed attack logs, avoiding external data upload.
- Security researchers note constraints on frontier AI models for cybersecurity investigations.
- The incident was reported to law enforcement, with forensic specialists involved.
- Prior security audit status unclear; no comment from Hugging Face on this.