Hugging Face AI platform infested with 100 malicious code-execution models, researchers warn

These models could create a persistent backdoor for attackers

clock • 3 min read
Hugging Face AI platform infested with 100 malicious code-execution models, researchers warn
Image:

Hugging Face AI platform infested with 100 malicious code-execution models, researchers warn

Security researchers have unearthed a troubling discovery on the Hugging Face AI platform, revealing the presence of approximately 100 machine learning (ML) models that harbour malicious code capable of executing on users' machines.

Hugging Face is a prominent collaborative platform for sharing AI models, datasets and applications. Although Hugging Face implements several security measures, including malware scanning and pi...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Microsoft plans to address Scope 3 emission surge

Green

New strategy encompasses more than 80 significant measures

clock 20 May 2024 • 2 min read
AI will spike data centre power demand 160% by 2030

Datacentre

A single ChatGPT query consumes nearly 10 times the electricity of a Google search

clock 20 May 2024 • 2 min read
IT Essentials: Sun, stress and security

Management

Burnout is the scourge of UK cyber - don't let it ruin your holidays

clock 20 May 2024 • 3 min read

More on Threats and Risks

Deepfake fraud costs engineering giant Arup £20m

Deepfake fraud costs engineering giant Arup £20m

An employee was tricked into participating in a video conference, featuring a digitally recreated version of the CFO

clock 20 May 2024 • 2 min read
Russian criminals use Lunar malware to breach European government agency

Russian criminals use Lunar malware to breach European government agency

Attackers thought to be part of Russia's FSB

Tom Allen
clock 17 May 2024 • 2 min read
Microsoft May Patch Tuesday fixes two actively exploited zero days

Microsoft May Patch Tuesday fixes two actively exploited zero days

Microsoft has fixed 60 Windows CVEs in its May Patch Tuesday update, two of which are actively exploited zero days. One is a critical vulnerability, earning an 8.8 CVSS rating.

John Leonard
clock 15 May 2024 • 3 min read