Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations
ID: 1568689f-aeae-51e0-b73e-6a8cc8e7dad1
STIX ID: report--1568689f-aeae-51e0-b73e-6a8cc8e7dad1
Feed Name: Wiz Blog
Wiz Research demonstrated that untrusted AI artifacts and build artifacts in Hugging Face could be abused to achieve remote code execution and multi-tenant compromise: a malicious Pickle-serialized PyTorch model executed code during inference, a crafted Dockerfile executed during build, and from those shells researchers accessed EKS node metadata to obtain credentials and Kubernetes tokens, enumerate secrets, and found write access to a shared internal container registry — together creating cross-tenant, supply-chain and sensitive-data exposure risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
