Tag: security
All the articles with the tag "security".
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
54 Fake CVEs in Four Days, and Nobody Checked
JFrog found a GitHub repo that published 55 CVE advisories in four days, 54 of them fabricated. The CVE pipeline has no reproduction requirement, and generative AI just made that cheap to exploit.
-
[QT] Apple's Bug Bounty Drowning in AI Noise
Apple's bug bounty program capped submissions to stem AI spam, but the cure might be worse than the disease.
-
JADEPUFFER's 19-Day Upgrade: Ransomware Built to Destroy AI Models
Sysdig TRT says the JADEPUFFER actor returned to the same unpatched Langflow instance with ENCFORGE, a Go ransomware that targets model checkpoints, vector databases and training data.