malicious actors
-
Hugging Face Hosts Malicious Software Posing as OpenAI Release
Cybersecurity researchers have detected a growing trend of malicious actors exploiting vulnerabilities in AI development platforms like Hugging Face. Attackers are using poisoned AI models and deceptive installers to infiltrate development environments, targeting peripheral components like scripts and setup instructions rather than core models. Traditional security tools struggle to detect this loader logic. Experts emphasize the need for comprehensive AI Bill of Materials (BOMs) to enhance supply chain visibility and fortify AI systems against these evolving threats.