Researchers scanned public repos and found 1,681 exposed Hugging Face API tokens belonging to Meta, Microsoft, Google, and others, many with write permissions
When I saw that @huggingface had minimal API key management I expected this. You must rotate your keys through automation and have developers use their own identities for testing. It's a pain, but as the research shows you risk bad guys tainting your data and revealing secrets.
Read all about how we exposed Hugging Face API tokens offered full access to Meta's Llama 2 >> https://www.theregister.com/ ... via @theregister #Cybersecurity #Research #Github #HuggingFace #VulnerabilityAlert #CyberAware #LassosSecurity #LLMsecurity #ModelTheft #TrainingDataPoi…