行业81°

TruffleSec CEO谈Hugging Face凭证泄露:25万密钥暴露

.@trufflesec co-founder and CEO Dylan Ayrey on the danger of exposed credentials and the Hugging Fac...

精选理由

Dylan Ayrey亲口讲Hugging Face那次泄露有多吓人,25万把有效密钥里还有能改Linux库的,赶紧检查自己有没有把密钥挂网上。

AI 摘要

Truffle Security联合创始人兼CEO Dylan Ayrey透露,与Hugging Face合作清理了训练集中暴露的凭证,发现约25万个有效密钥,许多直接影响供应链。其中一把密钥对某基础Linux库拥有直接推送权限,可能向全球大多数机器推送恶意软件。清理过程中,Hugging Face CTO告知OpenAI发生安全事件,事件响应中首先列出的就是被盗凭证。

图片来源 · a16z
原文 · a16z

.@trufflesec co-founder and CEO Dylan Ayrey on the danger of exposed credentials and the Hugging Fac...

. @trufflesec co-founder and CEO Dylan Ayrey on the danger of exposed credentials and the Hugging Face incident: "We partnered with Hugging Face to clean up credentials that had been exposed in training sets people hosted on their platform." "There were about a quarter million live keys, many of which had direct supply chain implications." "There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most machines on the planet." "While in the middle of doing that, the CTO of Hugging Face shoots me a note, 'There's this OpenAI thing that just happened, take a look.'" "And sure enough, the first thing listed in the incident response was stolen credentials. The path of least resistance is always the first step." @InsecureNature Your browser does not support the video tag. 🔗 View on Twitter roon @tszzl needless to say but if you have any API keys, eth wallet keys, user credentials, etc hanging out on the open internet in pastebins, GitHubs, etc now is the time to take it down before the tireless eagle eyes of a million models come looking 🔗 View Quoted Tweet 💬 2 🔄 0 ❤️ 14 👀 6816 📊 2 ⚡

TruffleSec CEO谈Hugging Face凭证泄露:25万密钥暴露 · AI 热点