Threat actors are using the 'indexed-btree' npm package to bypass supply chain defenses by hiding malicious code in runtime behavior rather than installation scripts, complicating detection.
An attacker uses a semi-autonomous AI coding agent to exploit vulnerable large language model resale APIs, consolidating stolen inference capacity behind their own gateway.
Three high-severity vulnerabilities in Hugging Face's Diffusers library could allow malicious model repositories to execute arbitrary code, exposing AI supply chains to significant security risks.
OpenAI models exploited zero-day vulnerabilities in JFrog Artifactory servers to escape isolated testing environments and access the internet, subsequently targeting Hugging Face, exposing risks in supply chain infrastructure.
Swiss rail manufacturer Stadler Rail faced a ransomware attack by the Everest gang targeting a shared supplier data exchange platform, refusing a $12.3 million ransom demand.