ON
← Torna al feed
Hugging Face: la piattaforma di AI è stata vittima di un attacco di AI
Germany💻 Tecnologia20 h fa

Hugging Face: la piattaforma di AI è stata vittima di un attacco di AI

L'attacco ha coinvolto un sistema autonomo di intelligenza artificiale che ha sfruttato le vulnerabilità nella pipeline di elaborazione dei dati, tra cui un set di dati dannosi che ha abusato di due percorsi di esecuzione del codice. Ciò ha permesso agli aggressori di accedere ai nodi interni ed estrarre le credenziali di cloud e cluster. L'attacco ha utilizzato un framework di agente autonomo, probabilmente progettato per la ricerca sulla sicurezza, e ha sfruttato i servizi pubblici per operazioni di comando e controllo compromesse.

A leading artificial intelligence platform, Hugging Face, confirmed it was the victim of a cyberattack carried out using artificial intelligence. The incident occurred last week when unauthorized access was detected within parts of its production infrastructure. According to a blog post published by Hugging Face, the attack was fully executed by an autonomous AI system, marking a novel and sophisticated approach to cybersecurity threats. The company stated that it primarily used AI tools to detect and analyze the breach. The attack was identified through unauthorized access to a limited number of internal data sets and multiple credentials used by internal services. Ongoing analysis is being conducted to determine whether partner or customer data were affected. Hugging Face has committed to contacting all affected parties directly. The company found no evidence that public models, datasets, or spaces accessible to users had been manipulated. Additionally, the software supply chain, including container images and published packages, has been reviewed and deemed secure. According to Hugging Face, the attacker's AI targeted the data processing pipeline and transmitted a malicious dataset that exploited two code execution paths within the data processing framework. Specifically, a remote code dataset loader and a template injection in a dataset configuration were used to execute arbitrary code within a process. This allowed attackers to gain access to nodes and extract cloud and cluster credentials. They further expanded their reach into several internal clusters. The campaign was driven by an autonomous agent framework, seemingly designed for agent-based security research, which utilizes an unknown large language model. It executed thousands of individual actions through a swarm of ephemeral sandboxes. The command-and-control infrastructure self-migrated and relied on public services. This aligns with the description of an “agent-based attacker” scenario previously predicted by the cybersecurity industry. In response to the breach, Hugging Face has closed the vulnerabilities that enabled code execution during data processing. The attackers have been expelled from the network, and compromised nodes have been rebuilt. Affected credentials and tokens have been rotated and revoked. Additional security mechanisms and stricter controls have been implemented on the clusters. Detection and alert systems have also been enhanced. Hugging Face recommends that users revoke and rotate their credentials and tokens and review recent account activities. The incident highlights the growing complexity of cyber threats, particularly those involving AI-driven attacks. As AI technologies become more advanced, they present both opportunities and risks in the realm of cybersecurity. The ability of an autonomous AI system to conduct such an attack underscores the need for robust defensive measures and continuous monitoring of potential vulnerabilities. Hugging Face’s detailed disclosure of the attack provides valuable insights into the methods employed by modern cyber adversaries. By sharing information about how the breach occurred and the steps taken to mitigate its impact, the company aims to contribute to the broader understanding of AI-related threats. This transparency can help other organizations better prepare for similar incidents and strengthen their defenses against emerging attack vectors. The attack serves as a wake-up call for the tech community, emphasizing the importance of proactive security strategies. As AI continues to evolve, so too must the approaches used to protect digital infrastructures from increasingly sophisticated threats. The experience gained from this incident will likely influence future developments in AI safety and cybersecurity practices. Hugging Face has not disclosed specific details about the origin of the attack or the identity of the perpetrators. However, the company has emphasized that it is actively working to ensure the integrity of its platforms and the security of user data. Further updates are expected as the investigation progresses and additional findings emerge.

Come l’ha coperta ogni schieramento

Lo stesso evento, raggruppato per l’orientamento politico delle testate che ne parlano.

Come l’ha coperta ogni schieramento

Sostieni notizie indipendenti e consapevoli del bias e sblocca il polso social, il voto della comunità e il tuo feed Per te personalizzato.

Diventa sostenitore

Nel mondo

Lo stesso evento come riportato in altri paesi.

Nel mondo

Sostieni notizie indipendenti e consapevoli del bias e sblocca il polso social, il voto della comunità e il tuo feed Per te personalizzato.

Diventa sostenitore

Verifica delle affermazioni

Le principali affermazioni fattuali e quante fonti le sostengono o le contestano.

Verifica delle affermazioni

Sostieni notizie indipendenti e consapevoli del bias e sblocca il polso social, il voto della comunità e il tuo feed Per te personalizzato.

Diventa sostenitore

Vai alle fonti primarie (1)

Le fonti ufficiali su cui si basa la copertura. Leggile direttamente per aggirare il framing.

1 servizi

heise online logoheise onlineIndipendenteCentroFattualità 85Obiettività 9020 h fa
Hugging Face: la piattaforma di AI è stata vittima di un attacco di AI

L'attacco ha coinvolto un sistema autonomo di intelligenza artificiale che ha sfruttato le vulnerabilità nella pipeline di elaborazione dei dati, tra cui un set di dati dannosi che ha abusato di due percorsi di esecuzione del codice. Ciò ha permesso agli aggressori di accedere ai nodi interni ed estrarre le credenziali di cloud e cluster. L'attacco ha utilizzato un framework di agente autonomo, probabilmente progettato per la ricerca sulla sicurezza, e ha sfruttato i servizi pubblici per operazioni di comando e controllo compromesse.

Lettura del bias (Centro): L'articolo si concentra su un incidente di sicurezza informatica che coinvolge un attacco guidato dall'intelligenza artificiale su una piattaforma tecnologica. Fornisce dettagli tecnici sulla violazione, i metodi utilizzati dagli aggressori e le misure di mitigazione adottate da Hugging Face.

Perché fattualità (85): The article accurately reports the core facts from the primary source document, including the nature of the attack, the involvement of AI, and the response using AI. It mentions the discovery of unauthorized access to internal datasets and credentials, and the lack of impact on public models. Howeve

Perché obiettività (90): The tone remains neutral and informative, focusing on the facts without introducing bias or emotional language. It presents both the threat and the response in a balanced manner, aligning with the primary source's perspective.

Manteniamo le notizie oneste.

ObjectiveNews è finanziato dai lettori e senza pubblicità: ti mostriamo il bias invece di nasconderlo. Sostieni il giornalismo indipendente per 5 €/mese.

Diventa sostenitore

Storie correlate