Malicious ML models exploit Pickle serialization flaw to evade detection on Hugging Face
The attack involves a technique involving “broken” pickle files to evade detection systems.
The attack involves a technique involving “broken” pickle files to evade detection systems.
The attackers appear to be manipulating SEO tactics to deploy the malware.
The attack appears to be global, with the majority of the malicious IP addresses originating from Brazil.
In brief: Trimble Cityworks zero-day exploited in the wild, a SmokeLoader campaign caught abusing 7-Zip zero-day, and more.
The campaign involves password-protected archives containing malicious JavaScript, VBScript, and LNK files.
The group’s attacks begin with spear-phishing campaigns targeting high-profile individuals in organizations
XE Group has leveraged at least two zero-day vulnerabilities in the VeraCore supply chain management software.
Once the backdoored package is installed, it grants the attacker remote access to the victim's system.
More than 1,500 Zyxel CPE Series devices remain exposed to the internet.
The threat has been used as part of the Lunar Peek campaign, targeting Linux-based network appliances.
Showing elements 921 - 930