Hugging Face is a tool tracked across 32 threat clusters and 111 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 27, 2026.
A critical remote code execution (RCE) vulnerability, tracked as CVE-2026-25874, has been identified in Hugging Face's LeRobot, an open-source robotics machine learning framework. This flaw, which has a CVSS severity…
Microsoft's Threat Intelligence unit has issued a warning about a cyber campaign targeting cryptocurrency investors and software developers through compromised npm packages. The malware, embedded in two specific…
A critical remote code execution vulnerability, CVE-2026-58116, has been identified in LLaMA-Factory versions up to 0.9.5. The flaw allows attackers to execute arbitrary Python code by supplying a malicious model path…
A critical remote code execution (RCE) vulnerability has been identified in the Hugging Face Transformers library, tracked as CVE-2026-4372. This flaw allows attackers to execute arbitrary code during model loading by…
On May 7, 2026, researchers identified malware in the Hugging Face repository Open-OSS/privacy-filter, which had impersonated OpenAI's legitimate Privacy Filter project. The malicious repository reached #1 on the…
In July 2026, researchers demonstrated that open-weight AI models can be easily poisoned, allowing attackers to implant backdoors for under $100. Katie Paxton-Fear successfully manipulated a model to execute remote code…
Pete Waterman, director of FedRAMP, stated that technology companies unable to promptly fix critical vulnerabilities should not sell to federal agencies. This warning follows a significant breach involving OpenAI and…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A critical vulnerability, CVE-2026-45829, in ChromaDB allows unauthenticated attackers to execute arbitrary code on exposed servers. This flaw affects the FastAPI server of the open-source vector database, which is…
A threat actor has integrated Anthropic's Claude Code AI into a large-scale credential harvesting operation named Bissa scanner. This operation has successfully exploited over 900 targets since September 2025, utilizing…