Hugging Face has disclosed information regarding a compromise of the infrastructure of the Hugging Face Spaces platform, which provides tools for creating demo applications for machine learning models and maintains a catalog of such applications. Employees of Hugging Face discovered traces of unauthorized access to the platform, which could have led to the leakage of user confidential data, including keys and tokens. The affected tokens have been revoked, and users have been notified with recommendations to update their keys and tokens, as well as to switch to new tokens that provide selective access control.
The investigation into the incident is not yet complete, and details have not been disclosed. It has been stated only that in recent days, Hugging Face has conducted substantial work to enhance the security of its infrastructure, completely ceased the use of org tokens, implemented a key management system (KMS), and deployed new tools for detecting token leaks. For the future, a complete cessation of the use of classic tokens with read and write access is planned.
Source: opennet.ru
