AI-as-a-Service Providers Vulnerable to PrivEsc and Cross-Tenant Attacks
ID: b1f9342a-a05f-59fc-8da6-94d1865a732b
STIX ID: report--b1f9342a-a05f-59fc-8da6-94d1865a732b
Feed Name: The Hacker News
New research found critical vulnerabilities in AI-as-a-service platforms (illustrated against Hugging Face) where untrusted Pickle-based PyTorch models and malicious Dockerfiles can trigger remote code execution, container escape, takeover of CI/CD pipelines, and internal container registry compromise — enabling cross-tenant access to private models. Researchers recommend avoiding Pickle in production, sandboxing untrusted models, enabling IMDSv2 with Hop Limit, and using MFA; Hugging Face reported it has patched the identified issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
