logo

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

ID: 876dbb54-eb1d-5e5c-bf36-3d28f8fcdc63

STIX ID: report--876dbb54-eb1d-5e5c-bf36-3d28f8fcdc63

Feed Name: TechCrunch Security News

Threat Score
60/100

Date Published: 2024-05-31

Date Updated: 2026-04-23

Author: Kyle Wiggers

...
...

Hugging Face disclosed that its security team detected unauthorized access to Spaces secrets—private tokens and keys used by hosted AI apps—and has revoked affected tokens, notified impacted users, and advised all users to rotate keys and consider finer-grained tokens; the company is investigating with external forensic specialists and has reported the incident to law enforcement and data protection authorities. The report also references earlier discovered vulnerabilities and suspicious uploads on the platform, which have increased scrutiny of Hugging Face’s security practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.