PyTorch — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
December 4, 2025
Last Seen
July 17, 2026

PyTorch is a technology platform tracked across 10 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity July 17, 2026.

Related Threat Clusters

  • Critical Vulnerabilities Found in PickleScan Tool for AI Models

    Three critical zero-day vulnerabilities have been identified in PickleScan, a tool used for scanning Python pickle files and PyTorch models. These flaws, all rated 9.3 on the CVSS scale, enable attackers to bypass…

    2 articles · Updated December 4, 2025
  • Critical Vulnerabilities Discovered in PickleScan Security Scanner

    Two critical vulnerabilities have been identified in PickleScan, a Python security scanner for serialized objects, affecting its blocklist-based protection. The first vulnerability (GHSA-g38g-8gr9-h9xp, CVSS 9.8)…

    2 articles · Updated June 18, 2026
  • AI Supply Chain Attacks and Model Poisoning Threats

    In July 2026, researchers demonstrated that open-weight AI models can be easily poisoned, allowing attackers to implant backdoors for under $100. Katie Paxton-Fear successfully manipulated a model to execute remote code…

    8 articles · Updated July 17, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • CVE-2026-56340: High-Risk Denial of Service Vulnerability in vLLM

    A critical vulnerability, CVE-2026-56340, affects vLLM versions 0.10.2 to 0.12.x, which lack sparse tensor validation in multimodal embeddings processing. Attackers can exploit this flaw by submitting malformed tensor…

    2 articles · Updated June 21, 2026
  • Critical Zero-Day Vulnerabilities Found in PickleScan Tool

    Multiple critical zero-day vulnerabilities have been identified in PickleScan, an open-source tool used for scanning machine learning models for malicious code. This tool is widely utilized in the AI community,…

    3 articles · Updated December 4, 2025
  • OpenSSF Reports Growth and New Security Resources Amid Rising Cyber Threats

    On May 21, 2026, the Open Source Security Foundation (OpenSSF) announced the addition of five new members and the launch of new security resources during its Community Day in Minneapolis. The foundation aims to enhance…

    11 articles · Updated May 21, 2026
  • Multiple Vulnerabilities Discovered in PyTorch Before Version 2.2.0

    Three vulnerabilities have been identified in PyTorch versions prior to 2.2.0, affecting various components. CVE-2024-31580 is a heap buffer overflow allowing Denial of Service, CVE-2024-31583 is a use-after-free…

    4 articles · Updated February 18, 2026
  • State-Sponsored Hackers Exploit Google's Gemini AI for Cyberattacks

    State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…

    162 articles · Updated February 12, 2026
  • Python Libraries in AI/ML Models Vulnerable to Metadata Poisoning

    Vulnerabilities have been identified in popular AI and ML Python libraries used in Hugging Face models, allowing remote attackers to embed malicious code in metadata. This code executes automatically when a file with…

    3 articles · Updated January 13, 2026

Recent Intelligence Reports

  • AI supply chain attacks — hivesecurity.gitlab.io · July 17, 2026
  • CVE-2026-56340: vLLM - Denial of Service via Unvalidated Multimodal Embeddings [HIGH] CVSS 8.8 Exploit Intelligence — Recent CVEs / 8h vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the pro — exploit-intel.com · June 21, 2026
  • CVE-2026-56340 - Exploits & Severity — Feedly · June 20, 2026
  • RAXE Labs advisory (GHSA-vvpj-8cmc-gx39) — raxe.ai · June 18, 2026
  • TrapDoor Attack Targets CLAUDE.md and .cursorrules With Zero — Letsdatascience · May 26, 2026
  • OpenSSF Notes Quarter of Growth with New Members, Added AI Security Resources, and ... — Linuxfoundation · May 21, 2026
  • Secure AI Framework (SAIF) taxonomy — saif.google · May 11, 2026
  • CVE-2024-31584 Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp. — Api.Msrc.Microsoft · February 18, 2026

CVSS v3.1 Breakdown