| |
Researchers scanned 7.6 petabytes of public datasets on Hugging Face and found 221,303 live credentials across 6,003 datasets, including 349 GitHub tokens and 318 Docker Hub tokens with dangerous permissions that could allow attackers to inject malicious code into widely-used software. One of the most critical discoveries was access to 393 GB of personally identifiable information affecting an estimated 3.7% of the global population. The findings highlight significant supply chain security risks in AI training data repositories and underscore the urgent need for vendors to revoke exposed credentials.
Read Full Article →
← More Tech news