Organizations using vulnerable versions of the Hugging Face Transformers library could unknowingly execute attacker-controlled code simply by loading a malicious AI model. Researchers at Pluto disclosed a remote code execution (RCE) vulnerability that bypasses the library’s built-in trust_remote_code=False security control, potentially exposing cloud credentials, SSH keys, API tokens, and other sensitive assets. “One poisoned field in a model’s config.json silently …
Author
Tracey Johnston
-
Looking up at the Moon tonight and wondering what exactly you’re looking …
-
Performance-wise, there’s no pedal-assist or throttle lag, as I’ve experienced on some …
-
Former tech executive and VC Sriram Krishnan is leaving the Trump administration …
-
AI’s infrastructure problem keeps moving. First, companies needed faster chips. Then they …
-
Amy Poehler is that fun, easygoing friend who’s somehow good at everything …
-
Meta has been quietly stashing dormant face recognition code on more than …
-
OpenAI announced a new feature that it says will provide additional protection …
-
Apple’s next big software moment is almost here. WWDC 2026 begins June …
-
In New York, legislators have passed a one-year moratorium on new data …
