Tag

Supply Chain Security

All articles tagged with #supply chain security

Autonomous AI Agent Breach Exposes Hugging Face Credentials
technology1 month ago

Autonomous AI Agent Breach Exposes Hugging Face Credentials

Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, stealing internal datasets and cloud credentials after exploiting a malicious dataset to trigger two code-execution vulnerabilities; the company evicted the attacker, rebuilt affected nodes, rotated credentials, and deployed enhanced detection while informing law enforcement and engaging external forensics. There is no current evidence of tampering with public models or Spaces, though the incident highlights evolving AI-driven attack risks. Users are advised to rotate access tokens and review account activity; Hugging Face also stresses having a vetted self-hosted model ready to use during incidents to avoid guardrail lockout and contain attacker data.

iPhone 18 Pro Leak Unveils A20 Pro, Under-Display Face ID, and Satellite 5G
technology1 month ago

iPhone 18 Pro Leak Unveils A20 Pro, Under-Display Face ID, and Satellite 5G

A Tata Electronics data breach reportedly exposed 630GB of Apple iPhone 18 Pro documents, detailing the A20 Pro chip with WMCM packaging, relocated RAM for better thermal management, a larger vapor chamber, a 24MP front camera, under-display Face ID, advanced computational photography, and a new C2 modem enabling 5G over satellite (Ganymede)—all while underscoring security risks in Apple’s supply chain.

Fake OpenAI Privacy Filter Repo Delivers Windows Infostealer on Hugging Face
security3 months ago

Fake OpenAI Privacy Filter Repo Delivers Windows Infostealer on Hugging Face

A clone of OpenAI's Privacy Filter on Hugging Face impersonated the legitimate model to distribute a Windows infostealer via a loader that downloads payloads through Base64, JSON Keeper, and PowerShell, then sets up a one-shot scheduled task to run the final malware and exfiltrate data (screenshots, crypto wallets, browser data) to a remote domain while attempting to evade detection by disabling AMSI/ETW; the repo peaked at #1 with about 244,000 downloads before being disabled, and researchers link it to similar loaders and ValleyRAT-related campaigns targeting open-source ecosystems.

Major React Native Security Flaws Endanger Millions of Developers
security9 months ago

Major React Native Security Flaws Endanger Millions of Developers

A critical security vulnerability in the '@react-native-community/cli' npm package, affecting millions of developers, allowed remote attackers to execute arbitrary OS commands via the Metro development server. The flaw, tracked as CVE-2025-11953 with a CVSS score of 9.8, has been patched in version 20.0.0, highlighting the importance of security scanning in the software supply chain.

U.S. and Australia Strengthen Critical Minerals Ties with New Agreements
world10 months ago

U.S. and Australia Strengthen Critical Minerals Ties with New Agreements

The US and Australia have established a framework to enhance cooperation and investment in securing the supply of critical minerals and rare earths vital for technology and defense industries, including joint project identification, financing, permitting reforms, and establishing a rapid response group to address supply vulnerabilities.