ServiceNow曝RCE漏洞且HuggingFace被袭
安全媒体披露,ServiceNow与Hugging Face近期遭遇安全威胁。
因源信息有限,目前仅确认ServiceNow的RCE漏洞已被在野利用。
同时,Hugging Face也确认遭遇安全入侵。
该漏洞为远程代码执行(RCE)漏洞,允许未授权用户执行代码。
Hugging Face遭遇入侵可能导致敏感模型数据泄露。
两起事件暴露出关键IT基础设施面临的严峻安全挑战。
专家建议,相关企业应尽快安装ServiceNow的安全补丁。
同时,AI开发者需加强对托管平台凭证的安全管理。
这表明企业在数字化转型中,必须高度重视供应链安全。
在野漏洞利用威胁企业核心资产
AI托管平台面临更严峻安全考验
供应链安全成为企业防护新重点
ServiceNow RCE Exploited Hugging Face Suffers Data Breach
The cybersecurity landscape marked two major incidents involving a pre-authentication Remote Code Execution (RCE) exploit targeting ServiceNow and a security breach at Hugging Face. Security researchers detected active, in-the-wild exploitation of the ServiceNow vulnerability, which allows unauthorized database access. Concurrently, Hugging Face disclosed a security breach affecting its Spaces platform, potentially exposing user secrets and Hugging Face tokens.
Due to limited information in the primary source, specific technical indicators and CVE identifiers remain high-level. The ServiceNow vulnerability enables attackers to execute arbitrary code remotely without prior authentication, posing severe risks to enterprise database integrity. Meanwhile, the Hugging Face breach involved unauthorized access to the Spaces container hosting environment. This compromise forced the platform to revoke certain user authentication tokens and recommend immediate credential rotation for all affected developers.
These concurrent security events highlight the growing threat surface for both enterprise software-as-a-service (SaaS) platforms and collaborative artificial intelligence (AI) development ecosystems. Organizations must prioritize rapid patch deployment for critical IT service management infrastructure to prevent unauthorized remote execution. Additionally, securing collaborative AI repositories remains vital as these platforms increasingly become primary targets for sophisticated supply chain cyberattacks.
Key Takeaways:
Active ServiceNow RCE exploitation threatens enterprise database security globally.
Hugging Face breach highlights growing supply chain risks in AI development.
Immediate credential rotation and rapid patching are critical to mitigate exposures.
Source: Original Article
查看原文 →
View Original →