Hugging Face published a security incident disclosure on their blog dated July 2026. The body of the post is not available in this record, but the disclosure indicates a security event affecting the platform. Hugging Face is a central hub for open-weights model hosting, datasets, and ML tooling, making any security incident potentially significant for the broader AI/ML ecosystem.
OpenAI and Hugging Face jointly disclosed a security incident that occurred during a model evaluation process. The incident involves two major AI organizations and touches on the security of evaluation infrastructure. Details are limited from the HN summary, but the primary source is an official OpenAI index page, suggesting a formal disclosure.
OpenAI and Hugging Face jointly published early findings from a security incident that occurred during AI model evaluation, describing advanced cyber capabilities observed during the event. The disclosure is framed as a lessons-learned report for defenders in the AI/ML ecosystem. The incident is notable as it involves two major AI infrastructure providers and touches on the security risks of running model evaluations at scale.
Hugging Face has announced a partnership with Protect AI to improve security for machine learning models hosted on the platform. The collaboration aims to address vulnerabilities in model files and supply chain risks that affect the broader ML community. Specific details about the technical implementation and scope of the security enhancements are not provided in the available content.
Hugging Face has announced a security partnership with Wiz Research aimed at improving security practices across the AI model hosting platform. The collaboration focuses on identifying and addressing vulnerabilities in AI infrastructure and model supply chain security. This partnership reflects growing attention to security risks specific to AI platforms, including malicious model files and shared infrastructure threats.
Hugging Face has announced a partnership with TruffleHog (TruffleSecurity) to integrate secret scanning into the Hugging Face platform. The integration aims to detect accidentally exposed credentials, API keys, and other secrets in model repositories and datasets. This addresses a growing security concern as the platform hosts an increasing volume of user-uploaded artifacts.
Hugging Face has announced a new partnership with Google Cloud, framed around building an open AI future. The blog post outlines collaboration between the two organizations, though the body content is not provided. This partnership likely involves deeper integration of Hugging Face's open-weights model hub and tooling with Google Cloud's infrastructure and services.
Hugging Face published a blog post describing their release engineering workflow for the huggingface_hub Python library, which ships updates weekly using a combination of AI assistance, open-source tools, and human review. The post covers the automated and semi-automated processes that enable high-cadence releases of a widely-used library in the ML ecosystem. This is relevant as a case study in AI-assisted software development workflows for a major ML infrastructure component.
Hugging Face has released huggingface_hub v1.0, marking a major milestone for the Python client library that underpins access to the Hugging Face Hub ecosystem. The v1.0 designation signals API stability and maturity after five years of development. This library is a foundational piece of open-source ML infrastructure, enabling model downloads, dataset access, and repository management across the broader ML community.