Tailscale and the OpenAI/Hugging Face attack, worth reading, "This is our very Canadian apology: sorry you stepped on our toes. The attack didn’t exploit Tailscale, and Tailscale didn’t cause the compromise. But, we didn't stop it. Next time, we will." tailscale.com/blog/hugging...
Tailscale in the Hugging Face intrusion: The good news and the bad news
An AI agent used a stolen Tailscale auth key at Hugging Face. Workload identity federation, flow logs, and safer defaults could have reduced the risk.
tailscale.com