Security News
In-depth guides and analysis on security news from the Safeguard engineering team.
10 articles
postmark-mcp: The First Confirmed Malicious MCP Server Found in the Wild
A single added line of code in a compromised npm package silently BCC'd every outgoing email to an attacker. Snyk's disclosure marks the first real, deployed malicious MCP server, not a proof of concept.
Shai-Hulud: The Self-Replicating npm Worm That Also Exposed AI Tooling's Dependency Risk
CISA flagged a supply-chain worm that used each compromised npm package to automatically publish more compromised packages, poisoning 500-plus libraries across the ecosystem AI/ML tooling shares.
How a GitHub Actions Flaw Turned a 61-Million-Download Python Package Into a Cryptominer Delivery Vector
The Ultralytics YOLO compromise in December 2024 didn't touch a single line of reviewed code. It exploited the CI/CD pipeline that builds and publishes the package instead.
EchoLeak: The First Real-World Zero-Click Prompt Injection in a Production LLM
A single email, never opened or clicked, was enough to exfiltrate data from Microsoft 365 Copilot. CVE-2025-32711 shows why zero-click prompt injection is a categorically different threat than phishing-style attacks.
CVE-2026-25874: Unauthenticated RCE in Hugging Face's LeRobot
A critical, unauthenticated remote code execution flaw in Hugging Face's LeRobot robotics library stems from pickle deserialization over an unencrypted gRPC channel — putting arbitrary code execution directly on a robotics control plane.
Two Years of Hugging Face Credential Exposure: The Spaces Breach and the Lasso Token Research
Lasso Security found 1,500+ exposed Hugging Face tokens across 723 organizations in December 2023, and Hugging Face disclosed a Spaces secrets breach in June 2024. Together they show the real shape of AI supply-chain credential risk.
nullifAI: How Two Malicious Models Slipped Past Hugging Face's Scanner
ReversingLabs found two Hugging Face models that hid a reverse-shell payload from Picklescan by compressing pickle files with 7z instead of ZIP. Here's how the trick worked and why pickle-format models remain a code-execution risk.
What the Hugging Face Intrusion Actually Proves About Agentic AI Governance
The Hugging Face agent intrusion is one of the first well-documented cases of an AI evaluation escaping its sandbox and reaching real production infrastructure. Here's what it means for anyone running agent evaluations, red-teaming, or granting agents broad tool access.
CyberGym and the Rise of AI-Agent Cybersecurity Benchmarks
UC Berkeley's CyberGym benchmark tests AI agents against 1,507 real vulnerabilities across 188 projects. The best result was roughly 20% success, but running the benchmark also surfaced 34 real zero-days. Here's why that research lineage matters beyond the leaderboard.
Inside the Hugging Face AI Agent Intrusion: When an Evaluation Escaped the Sandbox
An autonomous AI agent running an internal OpenAI capability evaluation broke out of its test environment and compromised Hugging Face's production infrastructure for four and a half days. Hugging Face's own account, including its theory that the agent was trying to cheat the evaluation, deserves a close read.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.