AI

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

Comment

Hugging Face
Image Credits: Hugging Face

Late Friday afternoon, a time window companies usually reserve for unflattering disclosures, AI startup Hugging Face said that its security team earlier this week detected “unauthorized access” to Spaces, Hugging Face’s platform for creating, sharing and hosting AI models and resources.

In a blog post, Hugging Face said that the intrusion related to Spaces secrets, or the private pieces of information that act as keys to unlock protected resources like accounts, tools and dev environments, and that it has “suspicions” some secrets could’ve been accessed by a third party without authorization.

As a precaution, Hugging Face has revoked a number of tokens in those secrets. (Tokens are used to verify identities.) Hugging Face says that users whose tokens have been revoked have already received an email notice and is recommending that all users “refresh any key or token” and consider switching to fine-grained access tokens, which Hugging Face claims are more secure.

It wasn’t immediately clear how many users or apps were impacted by the potential breach.

“We are working with outside cyber security forensic specialists, to investigate the issue as well as review our security policies and procedures. We have also reported this incident to law enforcement agencies and Data [sic] protection authorities,” Hugging Face wrote in the post. “We deeply regret the disruption this incident may have caused and understand the inconvenience it may have posed to you. We pledge to use this as an opportunity to strengthen the security of our entire infrastructure.”

In an emailed statement, a Hugging Face spokesperson told TechCrunch:

“We’ve been seeing the number of cyberattacks increase significantly in the past few months, probably because our usage has been growing significantly and AI is becoming more mainstream. It’s technically difficult to know how many spaces secrets have been compromised.”

The possible hack of Spaces comes as Hugging Face, which is among the largest platforms for collaborative AI and data science projects with over one million models, data sets and AI-powered apps, faces increasing scrutiny over its security practices.

In April, researchers at cloud security firm Wiz found a vulnerability — since fixed — that would allow attackers to execute arbitrary code during a Hugging Face-hosted app’s build time that’d let them examine network connections from their machines. Earlier in the year, security firm JFrog uncovered evidence that code uploaded to Hugging Face covertly installed backdoors and other types of malware on end-user machines. And security startup HiddenLayer identified ways Hugging Face’s ostensibly safer serialization format, Safetensors, could be abused to create sabotaged AI models.

Hugging Face recently said that it would partner with Wiz to use the company’s vulnerability scanning and cloud environment configuration tools “with the goal of improving security across our platform and the AI/ML ecosystem at large.”

More TechCrunch

Spotter, the startup that provides financial solutions to content creators, announced Tuesday the launch of its new AI-powered creative suite. Dubbed Spotter Studio, the solution aims to support YouTubers throughout the…

Spotter launches AI tools to help YouTubers brainstorm video ideas, thumbnails and more

This second fund is significant because Gupta expanded it beyond a corporate fund with one main LP – Prudential Financial – into one supported by a number of financial and…

Former Citi, Battery VC has new $378M fund that helps startups land Prudential, Mutual of Omaha, others as investors and customers

The oil and fracking giant says it is “working to identify effects” of the ongoing cyberattack on its oil and fracking operations.

Halliburton confirms data was stolen in ongoing cyberattack

Is Elon’s rumble in the Amazonian jungle on course for a technical knockout? Over the weekend, the Brazilian high court voted to uphold a ban on X that another judge issued…

Elon Musk’s Brazil battle wages on

Flexible green methanol, which is made without fossil fuels, could rid carbon pollution from a range of industries.

Oxylus Energy strikes “beautiful balance” to make e-fuels for aviation and shipping

French billionaire Xavier Niel is joining the board of directors of TikTok’s parent, ByteDance, the company told the South China Morning Post. It’s an interesting move as Niel isn’t a…

Xavier Niel replaces Coatue’s Laffont on board of TikTok parent ByteDance

The Netherlands’ data protection authority has imposed a penalty of €30.5M on Clearview AI for GDPR violations.

Clearview AI hit with its largest GDPR fine yet as Dutch regulator considers holding execs personally liable

X, the social network owned by Elon Musk, is finally rolling out one of the most sought-after features for direct messages: the ability to edit your message. Over the weekend,…

X now lets you edit DMs — here is how to use the feature

The Dubai-based startup, which now counts 50,000 retail and business customers in the UAE, has netted $22 million led by Altos Ventures.

Ziina banks $22M as growth explodes for the UAE-based fintech for small businesses

Fleet is launching several software services on top of its hardware-as-a-service proposition, from device management to cybersecurity and insurance.

Laptop-leasing startup Fleet wants to become the IT companion for small companies

The potential of Cercli’s payroll platform has attracted investor interest, leading to $4 million in seed funding.

Payroll startup Cercli inks $4M to build the ‘Rippling for the Middle East and North Africa’

Hospitals around the world regularly face bed shortages — an issue that can get exacerbated to breaking point when a health scare or other large-scale disaster occurs. A startup called…

‘Hospital at home’ startup Doccla raises $46 million for its European expansion

India’s fabless semiconductor startup BigEndian has raised $3 million in a seed round led by Vertex Ventures SEA and India.

BigEndian founders hope to use their deep chip experience to help establish India in semiconductors

SparkLabs — an early-stage venture capital firm that has made a name for itself for backing OpenAI as well as a host of other AI startups such as Vectara, Allganize,…

SparkLabs closes $50M fund to back AI startups

As companies grapple with the challenge of developing a sustainable business without sacrificing their core principles, open source has evolved from a niche approach to software development into the business…

Accel, Docker and Redis will discuss what’s next in open source as a business model at TechCrunch Disrupt 2024

Whether it’s a sophisticated cocktail party, a casual happy hour, a niche meetup, or a skill-building workshop, “Disrupt Week” offers you the flexibility to host a Side Event that truly…

Enhance your brand at TechCrunch Disrupt 2024 by hosting a Side Event

After joining the firm as an investor in 2022, Lu has seen how AI and new distribution platforms are changing the industry for the better.

A16z’s Joshua Lu says AI is already radically changing video games and Discord is the future

Only 5 days remain to grab a $200 discount on Student Passes for TechCrunch Disrupt 2024. This special offer ends on September 6 at 11:59 p.m. PT. Don’t miss out!…

Students and recent grads: 5 days left to save on TechCrunch Disrupt 2024 tickets

The tech industry has responded with a resounding outcry against SB 1047.

Sign or veto: What’s next for California’s AI disaster bill, SB 1047?

Even before Delta came forward, shareholders were looking for their pound of flesh, filing a class action lawsuit against CrowdStrike.

CrowdStrike faces onslaught of legal action from faulty software update

If you have never considered a search engine beyond Google, you might be surprised to see what else is out there.

Want to branch out beyond Google? Here are some search engines worth checking out

Customers of WazirX, the Indian cryptocurrency exchange that suffered a $234 million hack in July, are unlikely to recover their funds in full through the ongoing restructuring process, a company…

Customers of Indian crypto exchange WazirX unlikely to recover full funds

Validus, a Singapore-based digital lending platform for small and medium businesses, has secured $50 million in debt financing from HSBC under the ASEAN Growth Fund strategy. Validus will use the…

Validus, a Singapore-based digital SME lending platform, secures $50M debt financing to help enterprises in Indonesia

The Mac mini will be the next Apple device to say goodbye to USB-A, according to Bloomberg’s Mark Gurman. Apple customers have probably gotten used to seeing the familiar, rectangular…

Apple may ditch those old familiar USB-A ports in the new Mac mini

No matter who powerful generative AI becomes, writer Ted Chiang says it will never create true art. Chiang is one of the most admired science fiction authors writing today, best…

The case against AI art

Featured Article

Palantir’s CTO, and 13th employee, has become a secret weapon for Valley defense tech startups

Palantir CTO Shyam Sankar is determined to help Palantir become a driving force for defense tech startups.

Palantir’s CTO, and 13th employee, has become a secret weapon for Valley defense tech startups

As businesses experiment with embedding AI everywhere, one area starting to gain more attention is Emotion AI.

‘Emotion AI’ may be the next trend for business software, and that could be problematic

Featured Article

Why do so many home robots still suck?

Home robots’ unfulfilled potential is neither because of lack of demand on the part of consumers nor lack of effort from manufacturers.

Why do so many home robots still suck?

As we continue to monitor the growth of Africa’s tech ecosystem, it’s essential to highlight and analyze the biggest disclosed acquisitions.

From InstaDeep to Paystack: Here are Africa’s biggest startup exits and how much they raised

In the latest twist in Bolt’s aggressive fundraising efforts, the fintech company’s CEO appears to have made a veiled threat of legal action against Silverbear Capital, the investment bank whose…

Bolt reportedly threatens legal action against Silverbear Capital