Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 23, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 23, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 23, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 23, 2025

      SteamOS is officially not just for Steam Deck anymore — now ready for Lenovo Legion Go S and sort of ready for the ROG Ally

      May 23, 2025

      Microsoft’s latest AI model can accurately forecast the weather: “It doesn’t know the laws of physics, so it could make up something completely crazy”

      May 23, 2025

      OpenAI scientists wanted “a doomsday bunker” before AGI surpasses human intelligence and threatens humanity

      May 23, 2025

      My favorite gaming service is 40% off right now (and no, it’s not Xbox Game Pass)

      May 23, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      A timeline of JavaScript’s history

      May 23, 2025
      Recent

      A timeline of JavaScript’s history

      May 23, 2025

      Loading JSON Data into Snowflake From Local Directory

      May 23, 2025

      Streamline Conditional Logic with Laravel’s Fluent Conditionable Trait

      May 23, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      SteamOS is officially not just for Steam Deck anymore — now ready for Lenovo Legion Go S and sort of ready for the ROG Ally

      May 23, 2025
      Recent

      SteamOS is officially not just for Steam Deck anymore — now ready for Lenovo Legion Go S and sort of ready for the ROG Ally

      May 23, 2025

      Microsoft’s latest AI model can accurately forecast the weather: “It doesn’t know the laws of physics, so it could make up something completely crazy”

      May 23, 2025

      OpenAI scientists wanted “a doomsday bunker” before AGI surpasses human intelligence and threatens humanity

      May 23, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Hugging Face Discloses Unauthorized Access to Spaces Platform

    Hugging Face Discloses Unauthorized Access to Spaces Platform

    June 3, 2024

    Hackers penetrated artificial intelligence (AI) company Hugging Face’s platform to access its user secrets, the company revealed in a blog post.

    The Google and Amazon-funded Hugging Face detected unauthorized access to its Spaces platform, which is a hosting service for showcasing AI/machine learning (ML) applications and collaborative model development. In short, the platform allows users to create, host, and share AI and ML applications, as well as discover AI apps made by others.

    Hugging Face Hack Exploited Tokens

    Hugging Face suspects that a subset of Spaces’ secrets may have been accessed without authorization. In response to this security event, the company revoked several HF tokens present in those secrets and notified affected users via email.
    “We recommend you refresh any key or token and consider switching your HF tokens to fine-grained access tokens which are the new default,” Hugging Face said.
    The company has not disclosed the number of users impacted by the incident, which remains under investigation.

    Hugging Face said it has made “significant” improvements to tighten Spaces’ security in the past few days, including org tokens that offer better traceability and audit capabilities, implementing key management service, and expanding its systems’ ability to identify leaked tokens and invalidate them.

    It is also investigating the breach with external cybersecurity experts and reported the incident to law enforcement and data protection agencies.

    Growing Threats Against AI-as-a-Service Providers

    Risks faced by AI-as-a-service (AIaaS) providers like Hugging Face are increasing rapidly, as the explosive growth of this sector makes them a lucrative target for attackers who seek to exploit the platforms for malicious purposes.

    In early April, cloud security firm Wiz detailed two security issues in Hugging Face that could allow adversaries to gain cross-tenant access and poison AI/ML models by taking over the continuous integration and continuous deployment (CI/CD) pipelines.

    “If a malicious actor were to compromise Hugging Face’s platform, they could potentially gain access to private AI models, datasets and critical applications, leading to widespread damage and potential supply chain risk,” Wiz said in a report detailing the threat.

    One of the security issues that the Wiz researchers identified was related to the Hugging Face Spaces platform. Wiz found that an attacker could execute arbitrary code during application build time, enabling them to scrutinize network connections from their machine. Its examination revealed a connection to a shared container registry that housed images belonging to other customers, which the researchers could manipulate.

    Previous research by HiddenLayer identified flaws in the Hugging Face Safetensors conversion service, which could enable attackers to hijack AI models submitted by users and stage supply chain attacks.

    Hugging Face also confirmed in December that it fixed critical API flaws that were reported by Lasso Security.

    Hugging Face said it is actively addressing these security concerns and continues to investigate the recent unauthorized access to ensure the safety and integrity of its platform and users.

    Source: Read More

    Hostinger
    Facebook Twitter Reddit Email Copy Link
    Previous ArticleChina Increasingly Targeting Canadians with Cyber Operations
    Next Article Researcher Uncovers Exploited Flaw in Cox Modems That May Have Impacted Millions of Customers

    Related Posts

    Machine Learning

    This AI Paper Introduces Group Think: A Token-Level Multi-Agent Reasoning Paradigm for Faster and Collaborative LLM Inference

    May 24, 2025
    Machine Learning

    A Comprehensive Coding Guide to Crafting Advanced Round-Robin Multi-Agent Workflows with Microsoft AutoGen

    May 24, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    This AI Paper Explores Behavioral Self-Awareness in LLMs: Advancing Transparency and AI Safety Through Implicit Behavior Articulation

    Machine Learning

    New Runescape game hits number one on Steam

    News & Updates

    Trello adds 4 major project management features I didn’t know I needed – and they’re free

    News & Updates

    File Shredder – file deletion software

    Linux
    Hostinger

    Highlights

    Google Wallet now alerts you to loyalty card benefits you’re missing out on

    February 19, 2025

    Nearly 5,000 banks are now available in Google Wallet. Source: Latest news 

    DeepSeek API Introduces Context Caching on Disk: Reducing Input Token Price to 1/10

    August 9, 2024

    Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker

    April 12, 2024

    Fine-tune Anthropic’s Claude 3 Haiku in Amazon Bedrock to boost model accuracy and quality

    July 10, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.