Tag: ai supply chain
4 articles

Hugging Face Diffusers Flaws Expose AI Supply Chain to Code Execution Risk
Three high-severity vulnerabilities, dubbed "FaceHugger," have been discovered in the popular Hugging Face Diffusers library, which has been downloaded over 8.1 million times, putting the AI supply chain at risk of code execution attacks. These flaws can bypass a key safeguard, highlighting the urgent need for users to take action.

Hugging Face Breach Exposes AI Supply Chain Risks
Hugging Face confirmed a data breach attributed to an autonomous AI agent, revealing unauthorized access to internal datasets and credentials, but thankfully, its public-facing products showed no signs of tampering. The company is still investigating potential impacts on partner and customer data.

Global Agencies Unveil AI Supply Chain Risk Guidance with SBOMs
Global agencies have joined forces to release groundbreaking guidance on AI supply chain risk, outlining minimum elements for Software Bill of Materials (SBOMs) to enhance security and transparency. This crucial step forward aims to tackle the complex challenges of measuring and defining AI risks across organizations.

MCP Flaw Exposes AI Supply Chain to Remote Code Execution Risk
A critical flaw in the Model Context Protocol could allow attackers to run malicious code across dependent machines, posing a remote code execution risk that ripples through the AI supply chain. This structural weakness, discovered by cybersecurity researchers, highlights a vulnerable link in the AI ecosystem.