PyTorch compromised to demonstrate dependency confusion attack on Python environmentsSecurity Affairs·Jan 2, 18:57 UTC · Jan 2, 2023Vulnerability142
PyTorch Machine Learning Framework Compromised with Malicious DependencyThe Hacker News·Jan 5, 05:00 UTC · Jan 5, 2023Data breach157
Malicious PyTorch Lightning update hits AI supply chain securitySecurity Affairs·May 6, 07:04 UTC · May 6, 2026Malware42
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal CredentialsThe Hacker News·May 1, 16:27 UTC · May 1, 2026Ransomware57
Hugging Face, the GitHub of AI, hosted code that backdoored user devicesArs Technica · Security·Mar 1, 18:02 UTC · Mar 1, 2024Malware42
Malicious ML Models on Hugging Face Leverage Broken Pickle Format to Evade DetectionThe Hacker News·Feb 10, 04:09 UTC · Feb 10, 2025Exploit / PoC57
Threat Source newsletter (Jan. 5, 2023): Digging out of our inboxesCisco Talos·Jan 5, 20:09 UTC · Jan 5, 2023Ransomware57
Malicious Machine Learning Model Attack Discovered on PyPIInfosecurity Magazine·May 27, 14:00 UTC · May 27, 2025Malware42
Chainguard raises $140 million to strengthen open source software securityHelp Net Security·Jul 25, 00:00 UTC · Jul 25, 2024Vulnerability42
PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting DevelopersThe Hacker News·Mar 30, 05:08 UTC · Mar 30, 2024Malware42
New Hugging Face Vulnerability Exposes AI Models to Supply Chain AttacksThe Hacker News·Feb 27, 10:18 UTC · Feb 27, 2024VulnerabilityCVE-2023-496947
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackThe Hacker News·Jul 21, 07:34 UTC · Jul 21, 2026Ransomware in the wildCVE-2025-3248CVE-2026-33017CVE-2026-55255160
How software development's speed obsession enabled TeamPCP’s chaos crusadeCyberScoop·Jun 18, 23:03 UTC · Jun 18, 2026Ransomware57
Amazon EC2 G4 instances help accelerate ML inference and graphics-intensive workloadsHelp Net Security·Apr 20, 09:29 UTC · Apr 20, 2026Threat actor57
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing OpenThe Hacker News·Jun 4, 10:11 UTC · Jun 4, 2025Vulnerability142
New Attack Technique 'Sleepy Pickle' Targets Machine Learning ModelsThe Hacker News·Jun 17, 05:02 UTC · Jun 17, 2024Vulnerability42
TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning AttacksThe Hacker News·Jan 19, 02:51 UTC · Jan 19, 2024Vulnerability42
Python Developers Beware: Clipper Malware Found in 450+ PyPI Packages!The Hacker News·Feb 15, 00:00 UTC · Feb 15, 2023Malware42