HomeSecurityHackers stole tokens from AI platform Hugging Face

Hackers stole tokens from AI platform Hugging Face

AI platform Hugging Face says its Spaces platform was breached, allowing hackers to access authentication secrets for its members.

See also: Apple: Presents advanced AI open-source models that run on the device

Hugging Face hacker

Hugging Face Spaces is a repository of artificial intelligence applications created and submitted by community users , allowing other members to showcase them

"Earlier this week our team detected unauthorized access to our Spaces platform," Hugging Face warned in a blog post.

Hugging Face says it has already revoked the authentication tokens on the compromised secrets and notified those affected by the hacker attack via email.

However, they recommend that all Hugging Face Spaces users renew their tokens and switch to access tokens, which allow organizations to have tighter control over who has access to their AI models.

The company is working with external cybersecurity experts to investigate the breach and report the incident to law enforcement and data protection agencies.

See also: Phi-3 shows us the power of small AI language models

The Hugging Face platform says they have stepped up security measures in recent days due to the incident.

Hackers stole tokens from AI platform Hugging Face

As Hugging Face grows in popularity, it has also become a target for hackers, who are trying to abuse it for malicious activities.

In February, cybersecurity firm JFrog found about 100 instances of malicious AI ML models being used to execute malicious code on computer . One of the models opened a reverse shell that allowed a remote threat actor to gain access to a device running the code.

More recently, security researchers at Wiz discovered a vulnerability that allowed them to upload custom models and exploit container leaks to gain cross-tenant access to other customers' models.

See also: Malicious AI models appeared on the Hugging Face platform

Protecting an organization from data breaches like the one in Hugging Face by hackers is paramount in today’s digital age. Implementing strong security measures starts with educating employees about the importance of data security and recognizing phishing. Regularly updating and patching software can prevent vulnerabilities that hackers exploit. Additionally, using encryption for sensitive data ensures that even if information is intercepted, it remains inaccessible. Multi-factor authentication (MFA) adds another layer of protection by requiring multiple verification methods before granting access. Finally, developing a comprehensive incident response plan allows your organization to act quickly and effectively in the event of a breach, minimizing potential damage and restoring security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS