Hugging Face confirms which data sets and internal credentials are affected by the breach, and urges users to take action


Face-hugging, which is the platform for it Hosts AI models and datasetsIt said its internal data sets and service credentials were compromised in a hack last week. The company revealed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.

in Blog postThe company said the data set uploaded to its platform abused a vulnerability to run malicious code on its servers, allowing attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.

The company said it revoked and recovered the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and to review any suspicious activity on their accounts.

Hugging Face said it fixed the vulnerability that was abused during the cyberattack. While it is common for hackers to attempt to break into a company network using stolen employee credentials, keys, or a weak point in their security perimeter, this incident highlights the challenges companies like Hugging Face face when hackers attempt to abuse platforms and tools to access and steal sensitive data from the inside.

Hugging Face blamed the hack on an external AI agent, which carried out “several thousand individual actions across a swarm of short-lived sandboxes, relaying autonomous command and control over public services.”

The company did not immediately provide evidence for this claim when asked by TechCrunch.

Hugging Face said its anomaly detector detected the attack, and used an AI model to analyze server logs that kept a record of the cyberattack.

The company said it initially used a parametric AI model from a commercial provider, though it did not name a company, but found that analysis efforts were blocked by the provider’s guardrails. Instead, the company used its own large local language model, which it said provided the added benefit of not having to upload sensitive attack logs to the AI ​​company’s servers.

Security researchers have previously complained that some frontier models, such as Anthropic’s Mythos and Fable, are too restrictive, preventing defenders from inquiring about almost anything related to cybersecurity, including For defense and investigations.

Frontier AI model makers, including Anthropic, have fallen out with the Trump administration over concerns and concerns about the ability to use these models to launch offensive cyberattacks. Anthropic Until he had to withdraw Anecdote from general use after the US government imposed export controls on the model.

Hugging Face said it reported the incident to law enforcement and hired cybersecurity forensics specialists to investigate the breach and review its security.

It is not clear whether Hugging Face conducted a security audit of its systems before launching. A Hugging Face spokesperson did not respond to a request for comment on Monday.

When you make a purchase through the links in our articles, We may earn a small commission. This does not affect our editorial independence.

Leave a Reply

Your email address will not be published. Required fields are marked *