Report post

How many API tokens are exposed on hugging face?

With more than 1,500 tokens exposed, research highlights importance of securing supply chains in AI and ML Updated The API tokens of tech giants Meta, Microsoft, Google, VMware, and more have been found exposed on Hugging Face, opening them up to potential supply chain attacks. …

How many API tokens have been exposed?

Researchers at Lasso Security found more than 1,500 exposed API tokens on the open source data science and machine learning platform – which allowed them to gain access to 723 organizations' accounts. In the vast majority of cases (655), the exposed tokens had write permissions granting the ability to modify files in account repositories.

Are API tokens vulnerable to supply chain attacks?

More than 1,500 exposed API tokens belonging to tech giants like Meta, Microsoft, Google, and VMware were found on the Hugging Face platform, potentially making them vulnerable to supply chain attacks. The tokens had write permissions, allowing access to modify files in account repositories of 723 organizations.

The World's Leading Crypto Trading Platform

Get my welcome gifts