Key facts
- Hugging Face experienced a security breach affecting internal datasets and service credentials.
- The breach occurred due to a dataset exploiting a vulnerability to run malicious code on Hugging Face servers.
- Stolen credentials were accessed, and the company has revoked and rotated them.
- Users are advised to rotate their keys stored on the platform and monitor their accounts.
- The vulnerability has been fixed, and the incident has been reported to law enforcement.
Hugging Face, a prominent platform for hosting AI models and datasets, has confirmed a security breach that compromised its internal datasets and service credentials. The incident, disclosed on Friday, is still under investigation to determine if any customer or partner data was affected.
The company explained that a malicious dataset uploaded to its platform exploited a security vulnerability, enabling attackers to execute code on its servers and gain extensive access to internal systems. In response, Hugging Face has revoked and rotated the compromised credentials and is strongly advising its users to do the same for any keys stored on the platform and to scrutinize their accounts for unusual activity.
Hugging Face has since rectified the security flaw. The company attributed the attack to an external AI agent that performed numerous actions across numerous short-lived sandboxes. To analyze the attack, Hugging Face utilized its own local large language model, which offered the advantage of not requiring sensitive attack logs to be uploaded to a third-party provider's servers. This approach circumvented the limitations of some commercial frontier AI models, which have faced scrutiny for their security-related guardrails. The company has also reported the breach to law enforcement and enlisted cybersecurity forensic specialists for a thorough investigation.
