عاجل
ARالقيادة المركزية الأمريكية تستهدف مواقع إيرانية بعد هجمات الحرس الثوري في مضيق هرمزARالأسهم الكورية الجنوبية ترتفع مدعومة بأسهم الرقائق بعد خسائرARالحوثيون يعلنون "حصاراً بحرياً" على السعودية، والتحالف يتوعّد بالرد على أي تهديدARطهران تعلن "حرباً شاملة" مع واشنطن وتعطّل الملاحة في هرمز، وترامب يتوعّد إيران بثمن "أكبر بكثير"ARالجيش الأردني يعترض ثلاثة صواريخ إيرانيةARإسبانيا تحقق لقب كأس العالم الثانية بعد فوزها على الأرجنتين 1-0ARوزارة الخارجية الأمريكية تحذر مواطنيها في الشرق الأوسط من اضطرابات السفر واستهداف المصالحARالجيش الأردني يعترض ويسقط 3 صواريخ إيرانية استهدفت المملكةARالرئيس ترمب يفرض رسوماً جمركية جديدة بنسبة 50% على واردات كندية بقيمة 20 مليار دولارARحماس تعلن فوز خليل الحية برئاسة مكتبها السياسيARالقيادة المركزية الأمريكية تستهدف مواقع إيرانية بعد هجمات الحرس الثوري في مضيق هرمزARالأسهم الكورية الجنوبية ترتفع مدعومة بأسهم الرقائق بعد خسائرARالحوثيون يعلنون "حصاراً بحرياً" على السعودية، والتحالف يتوعّد بالرد على أي تهديدARطهران تعلن "حرباً شاملة" مع واشنطن وتعطّل الملاحة في هرمز، وترامب يتوعّد إيران بثمن "أكبر بكثير"ARالجيش الأردني يعترض ثلاثة صواريخ إيرانيةARإسبانيا تحقق لقب كأس العالم الثانية بعد فوزها على الأرجنتين 1-0ARوزارة الخارجية الأمريكية تحذر مواطنيها في الشرق الأوسط من اضطرابات السفر واستهداف المصالحARالجيش الأردني يعترض ويسقط 3 صواريخ إيرانية استهدفت المملكةARالرئيس ترمب يفرض رسوماً جمركية جديدة بنسبة 50% على واردات كندية بقيمة 20 مليار دولارARحماس تعلن فوز خليل الحية برئاسة مكتبها السياسي
Newsgather
رجوعHugging Face Discloses Internal Systems Breach Via AI Model Vulnerability
Hugging Face Discloses Internal Systems Breach Via AI Model Vulnerability
يتطور
TechCrunchقبل 10 ساعاتتقنية3 د قراءةUnited States

Hugging Face Discloses Internal Systems Breach Via AI Model Vulnerability

نظرة سريعة

  • Hugging Face, an AI model and dataset hosting platform, disclosed an internal systems breach last week.
  • Attackers exploited a security vulnerability in an uploaded dataset to run malicious code, gaining broader access and compromising service credentials.
  • The company has revoked credentials and urged users to do the same, while investigating potential customer data theft.

ملخص مُنشأ بالذكاء الاصطناعي

لماذا يهم

Hugging Face, a major platform for AI models and datasets, disclosed a security breach where a dataset exploited a vulnerability to compromise internal systems and service credentials. The company used its own LLM to analyze the attack after a commercial AI model's guardrails blocked analysis.

حجم الخط

Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.

In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.

The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts.

Hugging Face said it has fixed the vulnerability that was abused during the cyberattack. While it’s common for hackers to try to break into a company’s network using stolen employee credentials, keys, or a weak point in their security perimeter, this incident underscores the challenges that companies like Hugging Face face when hackers try to abuse platforms and tools to access and steal sensitive data from within.

Hugging Face blamed the breach on an external AI agent, which executed “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.”

The company did not immediately provide evidence for this claim when asked by TechCrunch.

Hugging Face said its own anomaly detection spotted the attack, and used an AI model to analyze server logs that kept record of the cyberattack.

The company said it initially used a frontier AI model from a commercial provider, though it didn’t name a company, but found that the analysis effort was blocked by the provider’s guardrails. Instead, the company used its own local large language model, which it said provided the added benefit of not having to upload sensitive attack logs to an AI company’s servers.

Security researchers have previously complained that some frontier models, like Anthropic’s Mythos and Fable, are heavily constrained, and prevent defenders from inquiring about almost anything relating to cybersecurity, including for defense and investigations.

Frontier AI model makers, including Anthropic, have butted heads with the Trump administration over fears and concerns about the ability to use these models for offensive cyberattacks. Anthropic was even forced to withdraw Fable from public use after the U.S. government enforced export controls on the model.

Hugging Face said it has reported the incident to law enforcement and roped in cybersecurity forensic specialists to investigate the breach and review its security.

It’s not clear if Hugging Face had performed a security audit of its systems before it launched. A Hugging Face spokesperson did not respond to a request for comment on Monday.

ما الذي يجب مراقبته

توقعات الذكاء الاصطناعي — احتمالات وليست حقائق

  • Law enforcement and cybersecurity specialists will continue investigating the breach.

    مرجح جداً · خلال أسابيع

أسئلة مفتوحة

  • Was any customer or partner data stolen?
  • What are the full findings of the cybersecurity forensic specialists?
  • Had Hugging Face performed a security audit before launch?

مواضيع ذات صلة

This article was originally published by TechCrunch.

أخبار ذات صلة

المزيد حول هذا الموضوعhugging face