PyTorch is a technology platform tracked across 10 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity July 17, 2026.
Three critical zero-day vulnerabilities have been identified in PickleScan, a tool used for scanning Python pickle files and PyTorch models. These flaws, all rated 9.3 on the CVSS scale, enable attackers to bypass…
Two critical vulnerabilities have been identified in PickleScan, a Python security scanner for serialized objects, affecting its blocklist-based protection. The first vulnerability (GHSA-g38g-8gr9-h9xp, CVSS 9.8)…
In July 2026, researchers demonstrated that open-weight AI models can be easily poisoned, allowing attackers to implant backdoors for under $100. Katie Paxton-Fear successfully manipulated a model to execute remote code…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A critical vulnerability, CVE-2026-56340, affects vLLM versions 0.10.2 to 0.12.x, which lack sparse tensor validation in multimodal embeddings processing. Attackers can exploit this flaw by submitting malformed tensor…
Multiple critical zero-day vulnerabilities have been identified in PickleScan, an open-source tool used for scanning machine learning models for malicious code. This tool is widely utilized in the AI community,…
On May 21, 2026, the Open Source Security Foundation (OpenSSF) announced the addition of five new members and the launch of new security resources during its Community Day in Minneapolis. The foundation aims to enhance…
Three vulnerabilities have been identified in PyTorch versions prior to 2.2.0, affecting various components. CVE-2024-31580 is a heap buffer overflow allowing Denial of Service, CVE-2024-31583 is a use-after-free…
State-backed hackers from China, Iran, North Korea, and Russia are utilizing Google's Gemini AI model to facilitate various stages of cyberattacks, including reconnaissance and post-compromise actions. Notably, the…
Vulnerabilities have been identified in popular AI and ML Python libraries used in Hugging Face models, allowing remote attackers to embed malicious code in metadata. This code executes automatically when a file with…