PyTorch compromised to demonstrate dependency confusion attack on Python environmentsSecurity Affairs·Jan 2, 18:57 UTC · Jan 2, 2023Vulnerability142
Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute CodeThe Hacker News·Dec 3, 11:44 UTC · Dec 3, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-10157+1 CVEs60
PyTorch Machine Learning Framework Compromised with Malicious DependencyThe Hacker News·Jan 5, 05:00 UTC · Jan 5, 2023Data breach157
Malicious PyTorch Lightning update hits AI supply chain securitySecurity Affairs·May 6, 07:04 UTC · May 6, 2026Malware42
Malicious PyTorch Package Downloaded Thousands of TimesInfosecurity Magazine·Jan 4, 10:00 UTC · Jan 4, 2023Industry30
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal CredentialsThe Hacker News·May 1, 16:27 UTC · May 1, 2026Ransomware57
Critical PickleScan Vulnerabilities Expose AI Model Supply ChainsInfosecurity Magazine·Dec 2, 16:00 UTC · Dec 2, 2025VulnerabilityCVE-2025-10155CVE-2025-10156CVE-2025-1015760
Warning: PyTorch Models Vulnerable to Remote Code Execution via ShellTorchThe Hacker News·Oct 9, 06:41 UTC · Oct 9, 2023VulnerabilityCVE-2023-43654CVE-2022-147160
Malicious ML models found on Hugging Face HubHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2025Exploit / PoC145
Hugging Face, the GitHub of AI, hosted code that backdoored user devicesArs Technica · Security·Mar 1, 18:02 UTC · Mar 1, 2024Malware42
Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade DetectionThe Hacker News·Feb 10, 04:09 UTC · Feb 10, 2025Exploit / PoC157
Malicious AI Models on Hugging Face Exploit Novel Attack TechniqueInfosecurity Magazine·Feb 7, 14:00 UTC · Feb 7, 2025Exploit / PoC45
AWS warns of ‘ShellTorch’ issue affecting code related to AI modelsThe Record·Oct 4, 16:35 UTC · Oct 4, 2023VulnerabilityCVE-2023-43654CVE-2022-147160
Threat Source newsletter (Jan. 5, 2023): Digging out of our inboxesCisco Talos·Jan 5, 20:09 UTC · Jan 5, 2023Ransomware57
Malicious Machine Learning Model Attack Discovered on PyPIInfosecurity Magazine·May 27, 14:00 UTC · May 27, 2025Malware42
Researchers Uncover Flaws in Popular OpenThe Hacker News·Dec 6, 11:28 UTC · Dec 6, 2024VulnerabilityCVE-2024-27132CVE-2024-6960CVE-2023-524560
How Intel is making open source accessible to all developersHelp Net Security·Nov 14, 00:00 UTC · Nov 14, 2024Vulnerability30
Chainguard raises $140 million to strengthen open source software securityHelp Net Security·Jul 25, 00:00 UTC · Jul 25, 2024Vulnerability42
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting DevelopersThe Hacker News·Mar 30, 05:08 UTC · Mar 30, 2024Malware42
New Hugging Face Vulnerability Exposes AI Models to Supply Chain AttacksThe Hacker News·Feb 27, 10:18 UTC · Feb 27, 2024VulnerabilityCVE-2023-496947
RedisAI and RedisGears address challenges customers have as they move AI into productionHelp Net Security·May 21, 00:00 UTC · May 21, 2020Phishing & fraud30
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackThe Hacker News·Jul 21, 07:34 UTC · Jul 21, 2026Ransomware in the wildCVE-2025-3248CVE-2026-33017CVE-2026-55255160
JadePuffer Returns With Ransomware Designed to Wipe AI ModelsInfosecurity Magazine·Jul 20, 14:05 UTC · Jul 20, 2026Ransomware in the wildCVE-2025-3248160
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItThe Hacker News·Jul 9, 05:17 UTC · Jul 9, 2026Exploit / PoCCVE-2026-3986150
How software development's speed obsession enabled TeamPCP’s chaos crusadeCyberScoop·Jun 18, 23:03 UTC · Jun 18, 2026Ransomware157
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory LeakThe Hacker News·May 11, 18:23 UTC · May 11, 2026VulnerabilityCVE-2026-7482CVE-2026-42248CVE-2026-42249160
Amazon EC2 G4 instances help accelerate ML inference and graphics-intensive workloadsHelp Net Security·Apr 20, 09:29 UTC · Apr 20, 2026Threat actor57
Patch, track, repeat: The 2025 CVE retrospectiveCisco Talos·Mar 5, 19:00 UTC · Mar 5, 2026Vulnerability in the wildCVE-2026-2138560
Oligo delivers runtime-native security for models and agentsHelp Net Security·Nov 20, 00:00 UTC · Nov 20, 2025Vulnerability155
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference FrameworksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025VulnerabilityCVE-2024-50050CVE-2025-30165CVE-2025-23254+1 CVEs60
CISO's Expert Guide To AI Supply Chain AttacksThe Hacker News·Nov 11, 11:58 UTC · Nov 11, 2025Ransomware60
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·Aug 19, 13:08 UTC · Aug 19, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI ServersThe Hacker News·Aug 6, 09:08 UTC · Aug 6, 2025Exploit / PoC in the wildCVE-2025-23319CVE-2025-23320CVE-2025-23334+3 CVEs60
Critical Vulnerabilities Found in NVIDIA's Triton Inference ServerInfosecurity Magazine·Aug 5, 15:45 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-23334+1 CVEs60
Chaining NVIDIA's Triton Server flaws exposes AI systems to remote takeoverSecurity Affairs·Aug 5, 07:35 UTC · Aug 5, 2025VulnerabilityCVE-2025-23319CVE-2025-23320CVE-2025-2333460
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing OpenThe Hacker News·Jun 4, 10:11 UTC · Jun 4, 2025Vulnerability242
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·May 17, 13:56 UTC · May 17, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60
⚡ Weekly Recap: Nation-State Hacks, Spyware Alerts, Deepfake Malware, Supply Chain BackdoorsThe Hacker News·May 6, 05:03 UTC · May 6, 2025MalwareCVE-2025-3928CVE-2025-1976CVE-2025-46271+33 CVEs60
Hugging Face platform continues to be plagued by vulnerable ‘pickles’CyberScoop·Feb 6, 16:34 UTC · Feb 6, 2025Exploit / PoC in the wild60