Hugging Face Security Breach Exposes Internal Datasets, Credentials, and Tokens
ID: 398aa036-101f-53af-9a5c-bb57e438589a
STIX ID: report--398aa036-101f-53af-9a5c-bb57e438589a
Feed Name: GBHackers
Hugging Face disclosed an intrusion that exploited code-execution flaws in its dataset-processing environment, enabling attacker-controlled execution, privilege escalation, credential harvesting, and lateral movement across internal clusters; the company detected the activity via AI-driven anomaly detection and used internal LLM agents to process ~17,000 attacker events, contained the intrusion, rotated credentials, and is engaging external forensics and law enforcement while investigating potential data exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
