HuggingFace is a organization tracked across 4 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity May 29, 2026.
HuggingFace is a software company known for building an open-source AI/ML ecosystem, including the Transformers library and the HuggingFace Hub for hosting models, datasets, and related tooling. As a central platform for sharing and deploying ML models and pipelines, it represents a high-value attack surface in cybersecurity, where credential leakage and supply-chain risks can impact a broad user base. The recent report highlighting widespread verified secrets leaks among leading AI companies underscores the security relevance to HuggingFace’s ecosystem and the importance of robust secret management and code hygiene.
A critical vulnerability, CVE-2026-45829, in ChromaDB allows unauthenticated attackers to execute arbitrary code on exposed servers. This flaw affects the FastAPI server of the open-source vector database, which is…
A sophisticated malware named MicrosoftSystem64 has been identified, leveraging Hugging Face datasets for data exfiltration. This malware, which masquerades as a legitimate Microsoft process, has been active since early…
A study by cloud security firm Wiz found that 65% of the Forbes AI 50 companies have leaked sensitive information, including API keys and access tokens, on GitHub. These leaks could expose organizational structures and…
A study by Wiz Security revealed that 65% of the Forbes AI 50 companies have leaked sensitive information, including API keys and tokens, on GitHub. The affected companies, valued collectively at over $400 billion, are…