Key facts
- Hugging Face experienced a security breach affecting internal datasets and service credentials.
- The breach occurred due to a dataset exploiting a vulnerability to run malicious code on Hugging Face servers.
- Stolen credentials were accessed, and the company has revoked and rotated them.
- Users are advised to rotate their keys stored on the platform and monitor their accounts.
- The vulnerability has been fixed, and the incident has been reported to law enforcement.
Hugging Face, a prominent platform for hosting AI models and datasets, has confirmed a security breach that compromised its internal datasets and service credentials. The incident, disclosed on Friday, is still under investigation to determine if any customer or partner data was affected.
The company explained that a malicious dataset uploaded to its platform exploited a security vulnerability, enabling attackers to execute code on its servers and gain extensive access to internal systems. In response, Hugging Face has revoked and rotated the compromised credentials and is strongly advising its users to do the same for any keys stored on the platform and to scrutinize their accounts for unusual activity.
