Safeguard
Tag

hugging-face

Safeguard articles tagged "hugging-face" — guides, analysis, and best practices for software supply chain and application security.

6 articles

AI Security

The Hugging Face Breach: What Changes When an AI Agent Runs the Intrusion

On 16 July 2026 Hugging Face disclosed that a malicious dataset gave an attacker code execution inside its data-processing pipeline, escalating to node-level access and internal cluster credentials over a single weekend — driven by an autonomous agent framework executing thousands of actions. Here's the anatomy, and what it means for anyone who treats a model registry as a trusted input.

Jul 28, 20266 min read
AI Security

nullifAI: Broken Pickles and the Hugging Face Detection Gap

ReversingLabs disclosed two malicious Hugging Face models that evaded Picklescan by using broken 7z-packed PyTorch archives. We unpack the technique.

Mar 23, 20266 min read
Incident Analysis

Hugging Face Token Exposure 2024 Analysis

Researchers found thousands of valid Hugging Face API tokens in public code and models. Analysis of the 2024 exposures and what they mean for ML supply chain.

Mar 21, 20268 min read
AI Security

AI Model Supply Chain Risks: Hugging Face and the New Attack Surface

As organizations download pre-trained models from Hugging Face and other model hubs, the AI supply chain introduces risks that traditional software security tools don't address.

Feb 8, 20265 min read
Software Supply Chain Security

Detecting Model Supply Chain Poisoning in 2026

Poisoning attacks against the model supply chain have moved from research to incident reports. What detection looks like when the attack surface includes weights.

Jan 22, 20266 min read
AI Security

Hugging Face Pickle Backdoor Research 2025

Pickle-serialized model files remain a live attack surface on Hugging Face. Here is what 2025 research disclosed about persistent backdoors and what defenders should do about it.

Jan 22, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

hugging-face — Safeguard Blog