KI-Unternehmen Hugging Face erkennt unbefugten Zugriff auf seine Spaces-Plattform

Teilen:

Artificial Intelligence (AI) company Hugging Face on Friday disclosed that it detected unauthorized access to its Spaces platform earlier this week.

“We have suspicions that a subset of Spaces’ secrets could have been accessed without authorization,” it said in an advisory.

Spaces offers a way for users to create, host, and share AI and machine learning (ML) applications. It also functions as a discovery service to look up AI apps made by other users on the platform.

Cybersecurity
In response to the security event, Hugging Space said it is taking the step of revoking a number of HF tokens present in those secrets and that it’s notifying users who had their tokens revoked via email.

“We recommend you refresh any key or token and consider switching your HF tokens to fine-grained access tokens which are the new default,” it added.

Hugging Face, however, did not disclose how many users are impacted by the incident, which is currently under further investigation. It has also alerted law enforcement agencies and data protection authorities of the breach.

The development comes as the explosive growth of the AI sector has landed AI-as-a-service (AIaaS) providers like Hugging Face in attackers’ crosshairs, who could exploit them for malicious purposes.

In early April, cloud security firm Wiz detailed security issues in Hugging Face that could permit an adversary to gain cross-tenant access and poison AI/ML models by taking over the continuous integration and continuous deployment (CI/CD) pipelines.

Cybersecurity
Previous research undertaken by HiddenLayer also unearthed flaws in the Hugging Face Safetensors conversion service that made it possible to hijack the AI models submitted by users and stage supply chain attacks.

“If a malicious actor were to compromise Hugging Face’s platform, they could potentially gain access to private AI models, datasets, and critical applications, leading to widespread damage and potential supply chain risk,” Wiz researchers noted in April.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:21 am, Juni 27, 2025
Wetter-Symbol 21°C
L: 20° | H: 22°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 63 %
Druck: 1020 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 27%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0 mm 0% 13 mph 68 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 8 mph 76 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 34°°C 0.2 mm 20% 8 mph 64 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
21° | 33°°C 0 mm 0% 11 mph 68 % 1016 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 24°°C 0 mm 0% 12 mph 59 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
25° | 27°°C 0 mm 0% 13 mph 47 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 13 mph 39 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 11 mph 68 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 85 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 8 mph 82 % 1023 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
25° | 25°°C 0 mm 0% 11 mph 61 % 1023 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,435.31
-0.57%
Ethereum(ETH)
€2,092.62
-1.25%
Fesseln(USDT)
€0.86
-0.02%
XRP(XRP)
€1.80
-4.10%
Solana(SOL)
€121.39
-1.87%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.137963
-1.44%
Shiba Inu(SHIB)
€0.000009
-2.72%
Pepe(PEPE)
€0.000008
-1.15%
Nach oben scrollen