New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks


Cybersecurity researchers have found that it’s possible to compromise the Hugging Face Safetensors conversion service to ultimately hijack the models submitted by users and result in supply chain attacks.
“It’s possible to send malicious pull requests with attacker-controlled data from the Hugging Face service to any repository on the platform, as well as hijack any models that are submitted







2024-02-27 10:18:00


0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *