Scworld Python Libraries in AI/ML Models Vulnerable to Metadata Poisoning
Article Content
Browse articles
Vulnerabilities have been identified in popular AI and ML Python libraries used in Hugging Face models, allowing remote attackers to embed malicious code in metadata. This code executes automatically when a file with the poisoned metadata is loaded. The affected libraries include NeMo, Uni2TS, and FlexTok, developed by Nvidia, Salesforce, and Apple in collaboration with EPFL VILAB.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (3)
Following this threat?
Track Hydra, Palo Alto Networks and CVE-2025-23304 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Emergence of PentestingEverything and Outis Remote Management Tool Two new cybersecurity tools have emerged: PentestingEverything, an open-source penetration testing knowledge base, and Outis, a custom remote administration tool (RAT). PentestingEverything offers a comprehensive resource covering 23 security domains, including methodologies and checklists for penetration testing. It…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…