Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.
In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.
The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts.
Hugging Face said it has fixed the vulnerability that was abused during the cyberattack. While it’s common for hackers to try to break into...
Copyright of this story solely belongs to techcrunch.com. To see the full text click HERE