The Register on MSN
Popular Python libraries used in Hugging Face models subject to poisoned metadata attack
The open-source libraries were created by Salesforce, Nvidia, and Apple with a Swiss group Vulnerabilities in popular AI and ML Python libraries used in Hugging Face models with tens of millions of ...
至顶头条 on MSN
热门Python库存在元数据投毒攻击漏洞
Hugging Face模型中使用的热门AI和机器学习Python库存在漏洞,允许远程攻击者在元数据中隐藏恶意代码。这些开源库包括英伟达的NeMo、Salesforce的Uni2TS和苹果与瑞士联邦理工学院合作开发的FlexTok。漏洞涉及Meta维护的Hydra库的instantiate()函数。当加载包含恶意元数据的文件时,恶意代码会自动执行。虽然目前尚未发现野外利用案例,但攻击面广泛,存在被 ...
近日,科技界再度震动,HuggingFace平台上广泛使用的多个热门AI和机器学习Python库被曝出存在元数据投毒攻击漏洞。根据至顶网的报道,这些库的下载量已经高达数千万次,漏洞的存在无疑为开发者和用户的安全敲响了警钟。
Salesforce is scaling back its reliance on large language models due to significant reliability issues, shifting focus to deterministic automation with its Agentforce product. Executives acknowledge a ...
The promise of the new agents is to solve the fragmentation problem that plagues finance departments. Unlike a sales leader ...
As AI coding tools become more sophisticated, engineers at leading AI companies are stopping writing code altogether ...
The popular open source AI assistant (aka ClawdBot, MoltBot) has taken off, raising security concerns over its privileged ...
2026年初,开源AI智能体OpenClaw(曾用名Clawdbot、Moltbot)以“开源版贾维斯”的姿态横扫全球技术圈。GitHub上68万颗星、Discord社区百万级用户、Cloudflare股价因关联概念单日暴涨10%——这场由奥地利开发 ...
After 15 years of 'Here's what I found on the web,' Siri is finally ready to have a conversation. Apple is reportedly ...
Who knew binge-watching YouTube could count as robotics R&D? 1X has plugged a 14-billion-parameter 1X World Model (1XWM) into ...
Salesforce leads in CRM market, controlling 23.9% in 2023, outpacing major rivals. Acquisitions fueled growth; post-IPO $10k investment in Salesforce now worth ~$645k. Despite industry challenges, ...
If you are still pasting every request into the same chat window, you might be capping your team’s potential. While ...
一些您可能无法访问的结果已被隐去。
显示无法访问的结果