3 ms·
0days ending in RCE (multiple!) for presumably closed source software are for the lack of a better phrase, labour of love. You run the exact same versions runn
by 0x5FC3 2mo ago
0days ending in RCE (multiple!) for presumably closed source software are for the lack of a better phrase, labour of love.
You run the exact same versions running on the target, blackbox test, fuzz it, craft an exploit, test, perfect it. For exploits which are of the memory kind, hook it to a debugger, decompile and what not. The exploits mentioned here seem to be code execution directly while processing input. Hugging Face taking as long to detect a very verbose blackbox attack against its production systems is quite appalling honestly.
I don't know if I buy the whole story though. It is inconsistent, too much undisclosed, too much money on the line.
- conradkay 2mo agoI find it trustworthy since we had Hugging Face's account first: https://huggingface.co/blog/security-incident-july-2026 https://huggingface.co/blog/security-incident-july-2026 I don't think they have any real motive to shill OpenAI, probably closer to the opposite since they're so involved in open weights