The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation.
Hugging Face identified unauthorized access to a limited set of internal datasets and several credentials used by its services.
They then chained vulnerabilities and stolen credentials across OpenAI and Hugging Face systems while seeking benchmark answers.
The primary disclosures establish that the open model helped Hugging Face reconstruct the intrusion and supported its response.
For now, the public record shows a coalition, a policy position, several member commitments, and one iden…