ON
← Back to feed
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
United States🏛️ PoliticsCenter23 hr. ago

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face, an AI platform hosting models and datasets, confirmed a security breach affecting its internal systems and credentials. The breach occurred due to a malicious dataset exploiting a security vulnerability, allowing attackers to escalate privileges and access internal systems. The company stated it has revoked stolen credentials and urged users to check their own keys. They attributed the breach to an external AI agent operating through automated processes. Hugging Face used its own AI model for analysis rather than a third-party provider due to restrictions. The incident highlights ongoing challenges in securing AI infrastructure, with security experts criticizing frontier models for limiting defensive capabilities. The company has reported the breach to authorities and enlisted cybersecurity experts for further investigation.

Hugging Face confirmed on Friday that a recent cyberattack compromised its internal datasets and service credentials. The breach occurred last week, according to the company, and it is currently investigating whether any customer or partner data was accessed. In a blog post, Hugging Face explained that a dataset uploaded to its platform exploited a security flaw to execute malicious code on its servers, enabling attackers to elevate their privileges and access broader parts of the company's internal infrastructure. The company stated that it has revoked and rotated the stolen credentials and is urging users to do the same with any keys they have stored on the platform. Users are also advised to review their accounts for any unusual activity. Hugging Face claims it has resolved the specific vulnerability that was exploited during the attack. However, the incident highlights the ongoing challenge faced by organizations like Hugging Face when adversaries exploit platforms and tools to access and potentially steal sensitive information. Hugging Face attributed the breach to an external AI agent, which carried out numerous actions across multiple temporary sandboxes. These actions included self-migrating command-and-control operations hosted on publicly accessible services. Despite being contacted by TechCrunch, the company did not provide immediate evidence supporting this assertion. The breach was detected by Hugging Face's own anomaly detection system, which analyzed server logs using an AI model. Initially, the company attempted to use a frontier AI model from a commercial provider to analyze the logs. However, this effort was hindered by the provider’s restrictions. As a result, Hugging Face opted to use its own locally hosted large language model, which allowed for the analysis without uploading sensitive data to third-party servers. Security experts have raised concerns about certain frontier models, such as Anthropic’s Mythos and Fable, which impose strict limitations that can impede cybersecurity investigations. These models have been the subject of disputes with the Trump administration, particularly regarding their potential use in offensive cyber operations. Anthropic was compelled to remove Fable from public availability following the imposition of export controls by the U.S. government. Hugging Face has informed law enforcement authorities about the incident and enlisted cybersecurity forensic specialists to conduct a thorough investigation and evaluate its security measures. There is uncertainty surrounding whether Hugging Face conducted a prior security audit of its systems before launching its services. A representative from the company did not respond to a request for clarification on Monday. The incident raises important questions about the security practices of platforms hosting AI models and datasets, especially given the increasing sophistication of cyber threats targeting such environments.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (1)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

TechCrunch logoTechCrunchIndependentCenterFactual 85Objective 7523 hr. ago
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face, an AI platform hosting models and datasets, confirmed a security breach affecting its internal systems and credentials. The breach occurred due to a malicious dataset exploiting a security vulnerability, allowing attackers to escalate privileges and access internal systems. The company stated it has revoked stolen credentials and urged users to check their own keys. They attributed the breach to an external AI agent operating through automated processes. Hugging Face used its own AI model for analysis rather than a third-party provider due to restrictions. The incident highlights ongoing challenges in securing AI infrastructure, with security experts criticizing frontier models for limiting defensive capabilities. The company has reported the breach to authorities and enlisted cybersecurity experts for further investigation.

Bias read (Center): While the article discusses cybersecurity and AI technology, which could be seen as politically relevant, the focus remains on technical aspects of the breach and operational responses. There is no overt ideological framing or emphasis on political agendas. The discussion around frontier AI models'

Why factuality (85): The article accurately reports the breach affecting internal datasets and credentials, aligns with the primary source document regarding the AI-driven nature of the attack, and mentions the revocation of credentials. However, it omits specific details about the AI agent framework and the use of GLM

Why objectivity (75): The article presents the facts neutrally but includes some subjective phrasing such as 'challenges that companies like Hugging Face face,' implying a critique of the situation. It also lacks balance by not mentioning the company's proactive steps or the collaboration with cybersecurity experts.

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories