ELSEIF
Your brief EB
183 stories from 71 feeds 32 clusters Refreshed 9 minutes ago next pull 13:20

TECH Signal 223

Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets

WHY IT MATTERS

Secrets leaked into public AI training datasets can be discovered and exploited by anyone, creating a direct path to software supply chain attacks, cloud takeovers, and massive data exposure. The presence of live GitHub tokens with write access and Docker Hub push privileges means malicious actors could alter widely installed software.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The scan found 349 live GitHub personal access tokens, including 223 with full repo write access and 130 capable of rewriting CI workflows, posing direct software supply chain risks.

02

Live credentials discovered included 8,557 GCP service-account keys across 3,811 projects, 8,594 working database logins, and one key that granted access to 393 GB of PII covering an estimated 3.7% of the global population.

03

Hugging Face's CTO contributed native storage-bucket scanning support to TruffleHog following responsible disclosure of the findings.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Hacker News Scanning 7.6 Petabytes of HuggingFace Training Data for Secrets Open ↗