Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > AI supply chain
#AI supply chain

Critical HuggingFace Transformers Flaw CVE-2026-4372 Enables Silent RCE — 232 Million Installs at Risk

8 June 2026  |  dark6  |  AI

A critical RCE vulnerability in HuggingFace Transformers (CVE-2026-4372) allows attackers to silently execute code by loading a malicious AI model, bypassing the trust_remote_code=False security control. Over 232 million...

>> read more

JINX-0164: Crypto-Targeting APT Uses LinkedIn Job Lures and Fake Meeting Apps to Deploy macOS Malware and Poison npm Supply Chain

30 May 2026  |  dark6  |  Malware

Threat actor JINX-0164 is targeting cryptocurrency developers via fake LinkedIn profiles, luring them into downloading custom macOS malware (AUDIOFIX and MINIRAT) that steals credentials, cloud tokens, and crypto...

>> read more

AI Supply Chain Attack: 575+ Malicious Skills on Hugging Face and ClawHub Deliver Trojans, Cryptominers, and AMOS Stealer

9 May 2026  |  dark6  |  AI

Threat actors have uploaded 575+ malicious AI skills to ClawHub's OpenClaw ecosystem and abused Hugging Face repositories to deliver trojans, cryptominers, and AMOS Stealer. The campaign uses indirect...

>> read more