Hugging Face Discloses Cyberattack Compromising Internal Systems and Credentials
Hugging Face, a platform known for hosting AI models and datasets, has confirmed a cyberattack that compromised its internal datasets and service credentials. The breach was disclosed after a dataset uploaded to the platform exploited a security vulnerability, allowing attackers to execute malicious code and gain broader access to Hugging Face's internal systems. The company has since revoked and rotated the compromised credentials and urged users to do the same. The vulnerability has been patched, and the company is investigating the incident with cybersecurity forensic specialists. The attack was attributed to an external AI agent executing numerous actions across short-lived sandboxes.