Issue 239: Hugging Face API token breach, SonicWall firewalls exploit, Kubernetes API gateway guide
Brief
This week, we have news of a recent API token breach affecting the popular Hugging Face AI portal and a vulnerability in the SonicWall firewall affecting 178,000 instances. We also have a comprehensive API security checklist and a guide on selecting the most suitable API gateway for Kubernetes environments.
Finally, we have a practical guide on securing APIs using the Express framework and a pair of blogs from Dana Epp.
Breach: Hugging Face AI platform exposes API tokens
This week’s main news is recent research indicating large-scale leakage of API tokens on the popular Hugging Face AI portal.
Hugging Face hosts over 500,000 AI models and 250,000 datasets for developers working on LLMs and Generative AI projects and can be thought of as the GitHub for AI developers. The platform provides an API and Python library to enable developers to access their models and data.
