728 x 90

Hugging Face confirms breach of credentials and affected internal data sets and urges users to take action | TechCrunch

Hugging Face confirms breach of credentials and affected internal data sets and urges users to take action | TechCrunch

Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in an attack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said

Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in an attack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.

In a blog post, the company said that a dataset uploaded to its platform abused a security vulnerability to execute malicious code on its servers, allowing attackers to escalate its permissions and gain broader access to Hugging Face’s internal systems.

The company said it revoked and rotated the stolen credentials that were accessed. It urged users to do the same with keys stored on the platform and review any suspicious activity on their accounts.

Hugging Face said it had fixed the vulnerability that was abused during the cyberattack. While it is common for hackers to attempt to enter a company’s network using stolen employee credentials, keys, or a weak point in its security perimeter, this incident highlights the challenges companies like Hugging Face face when hackers attempt to abuse platforms and tools to access and steal sensitive data from within.

Hugging Face blamed the breach on an external AI agent, which executed “many thousands of individual actions in a swarm of short-lived sandboxes, with self-migrating command and control organized into utilities.”

The company did not immediately provide evidence for this claim when asked by TechCrunch.

Hugging Face said its own anomaly detection detected the attack and used an artificial intelligence model to analyze server logs that kept track of the cyberattack.

The company said it initially used a frontier AI model from a commercial vendor, although it did not name a company, but found that the analysis effort was blocked by vendor barriers. Instead, the company used its own large local language model, which it said provided the added benefit of not having to upload sensitive attack logs to an AI company’s servers.

Security researchers have previously complained that some frontier models, such as Anthropic’s Mythos and Fable, are highly restricted and prevent defenders from asking about almost anything related to cybersecurity, even for defense and investigations.

Makers of Frontier AI models, including Anthropic, have clashed with the Trump administration over fears and concerns about the ability to use these models for offensive cyberattacks. Anthropic was even forced to remove Fable from public use after the US government imposed export controls on the model.

Hugging Face said it reported the incident to authorities and hired forensic cybersecurity specialists to investigate the breach and review its security.

It is unclear whether Hugging Face had conducted a security audit of its systems before its launch. A spokesperson for Hugging Face did not respond to a request for comment Monday.

When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.

Keep following us for the latest insights.

Posts Carousel

Latest Posts

Top Authors

Most Commented

Featured Videos