cognitive cybersecurity intelligence

News and Analysis

Search

Hugging Face, the GitHub of AI, hosted code that backdoored user devices

Security firm JFrog claims that around 100 submissions of AI code to the infrastructure provider Hugging Face contained hidden or harmful elements. Ten were categorised as “truly malicious”, compromising user security. One model opened a reverse shell providing remote internet control of user devices. The submitted codes which bypassed Hugging Face’s malware scanner used a technique known as “pickle”, a Python process which can be exploited by hackers.

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts