Tag
#AI supply chain
2 stories taggedAI supply chain.

AI Security
Three flaws in Hugging Face's Diffusers library let booby-trapped AI models run code on your machine
Researchers found ways to bypass the safety switch meant to stop untrusted AI models from executing hidden instructions when loaded.
3 min read

AI Security
Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field
CVE-2026-4372 lets an attacker own any machine that loads a poisoned model. No warnings, no prompts, no trace. The trust_remote_code flag turned out to be decorative.
3 min read