Cybersecurity

Hugging Face breach: rotate tokens, review activity

1 min read

0 0
XWhatsAppTelegramLinkedIn

Hugging Face has confirmed a security breach that compromised internal datasets and credentials. The company disclosed the incident on May 30, 2024, stating that unauthorized access was detected in its internal systems, potentially exposing secrets such as access tokens used by users to authenticate with the platform. Hugging Face is urging all users to rotate any access tokens stored on the platform and to review their account activity for suspicious behavior. The breach affects the broader AI community, as Hugging Face hosts over 500,000 models and 250,000 datasets used by researchers and developers worldwide. The company has not disclosed the exact number of affected users or the root cause of the breach, but it has implemented additional security measures, including revoking compromised tokens and enhancing system monitoring. This incident follows a trend of increasing cyberattacks targeting AI infrastructure, highlighting the importance of securing credentials and regularly auditing access. Hugging Face advises users to enable two-factor authentication and to use fine-grained access tokens with limited permissions. The company is working with law enforcement and cybersecurity experts to investigate the breach and prevent future occurrences.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.