HuggingFace — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 10, 2025
Last Seen
May 29, 2026

HuggingFace is a organization tracked across 4 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity May 29, 2026.

Overview

HuggingFace is a software company known for building an open-source AI/ML ecosystem, including the Transformers library and the HuggingFace Hub for hosting models, datasets, and related tooling. As a central platform for sharing and deploying ML models and pipelines, it represents a high-value attack surface in cybersecurity, where credential leakage and supply-chain risks can impact a broad user base. The recent report highlighting widespread verified secrets leaks among leading AI companies underscores the security relevance to HuggingFace’s ecosystem and the importance of robust secret management and code hygiene.

Related Threat Clusters

  • Critical ChromaDB Vulnerability Enables Remote Code Execution

    A critical vulnerability, CVE-2026-45829, in ChromaDB allows unauthenticated attackers to execute arbitrary code on exposed servers. This flaw affects the FastAPI server of the open-source vector database, which is…

    4 articles · Updated May 20, 2026
  • MicrosoftSystem64 Malware Exploits Hugging Face for Data Theft

    A sophisticated malware named MicrosoftSystem64 has been identified, leveraging Hugging Face datasets for data exfiltration. This malware, which masquerades as a legitimate Microsoft process, has been active since early…

    3 articles · Updated May 29, 2026
  • 65% of AI Companies Expose API Keys on GitHub

    A study by cloud security firm Wiz found that 65% of the Forbes AI 50 companies have leaked sensitive information, including API keys and access tokens, on GitHub. These leaks could expose organizational structures and…

    4 articles · Updated November 11, 2025
  • 65% of Leading AI Companies Leak Sensitive Data on GitHub

    A study by Wiz Security revealed that 65% of the Forbes AI 50 companies have leaked sensitive information, including API keys and tokens, on GitHub. The affected companies, valued collectively at over $400 billion, are…

    6 articles · Updated November 11, 2025

Recent Intelligence Reports

  • MicrosoftSystem64 Malware Uses HuggingFace Datasets for Stealthy Data Exfiltration — Cybersecuritynews · May 29, 2026
  • Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution — Thecyberexpress · May 20, 2026
  • 65% of Leading AI Companies Found With Verified Secrets Leaks — Infosecurity-Magazine · November 10, 2025

CVSS v3.1 Breakdown