Back to directory
WRITEUP #370

Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations

AI / LLMAIMalicious AI modelCloudCI/CDRCEInsecure deserializationPrivilege escalationSupply chain attackCross-tenant vulnerability
by@shirtamari(Shir Tamari)
Bounty
200
Program
Hugging Face
Published
Apr 4, 2024
Added to HackDex
May 8, 2024
Read Full Writeuphttps://www.wiz.io/blog/wiz-and-hugging-face-address-risks-to-ai-infrastructure
RELATED WRITEUPS
From MLOps to MLOops: Exposing the Attack Surface of Machine Learning Platforms
AI / LLMAI
SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts
AI / LLMAI
Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve) (CVSS 9.9, CVSS 9.8) Walkthrough
AI / LLMAI
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
AI / LLMCI/CD
Unveiling Remote Code Execution in AI chatbot workflows 💵
AI / LLMAI

Built with ❤️ by Shubham Rawat