Security Insights

Latest threat analysis, industry news, and security best practices from our expert team.

Has:
ai-supply-chain9 articles
Sep 14, 2026

Beijing Responds to Anthropic CEO's Call to Curb Chinese AI: What the AI Geopolitical Escalation Means for Enterprise Defenders

Introduction China's Ministry of Foreign Affairs has publicly pushed back against Anthropic CEO Dario Amodei's recent essay calling for curb...

criticalzero-daycve
Vulnerability ManagementRead Now
Sep 13, 2026

AI Supply Chain Under Attack: Defending Against Malicious Open-Source Models and Packages in 2026

The AI Supply Chain Problem Is No Longer Theoretical Pierluigi Paganini's Security Affairs newsletter Round 594 puts its finger on something...

sigma-rulekql-detectionthreat-hunting
Vulnerability ManagementRead Now
Sep 12, 2026

Hawley Probe of OpenAI Over Hugging Face Breach: Defending Against AI Supply Chain and Token Exposure Risk

Congressional Scrutiny Meets a Real Defensive Problem Senator Josh Hawley (R-MO) has opened an inquiry into OpenAI following the Hugging Fac...

criticalzero-daycve
Vulnerability ManagementRead Now
Sep 5, 2026

Nvidia's $13B Hugging Face Acquisition: Securing the Open-Source AI Model Supply Chain After Consolidation

Introduction Nvidia has announced its intent to acquire Hugging Face — the de facto central repository for open-source AI models, datasets, ...

criticalzero-daycve
Vulnerability ManagementRead Now
Sep 3, 2026

llm-gemini 0.34 and Gemini 3.8 Flash: A Defender's Guide to Safely Adopting LLM CLI Tooling in Security Operations

Introduction On September 2, 2026, Simon Willison released llm-gemini 0.34, the Gemini plugin for his widely used llm command-line toolkit. ...

criticalzero-daycve
Vulnerability ManagementRead Now
Aug 17, 2026

Hugging Face Supply-Chain Attack & PHANTOM-B: Threat Modeling Lessons for Defending AI/ML Pipelines

Introduction When Adam Shostack — arguably the most authoritative voice in threat modeling alive — says he was "blown away" by an attack dis...

criticalzero-daycve
Vulnerability ManagementRead Now
Aug 3, 2026

AI Supply Chain Compromise: Detecting Arbitrary Code Execution in Hugging Face Diffusers

Introduction The integration of Artificial Intelligence into production environments has expanded the attack surface for defenders, introduc...

criticalzero-daycve
Vulnerability ManagementRead Now
Jun 12, 2026

The Gentlemen RaaS & AI Supply Chain Poisoning: SystemBC, AMOS Stealer, and CVE-2024-55591 Exploitation

Threat Summary Recent OTX pulse data reveals a dual-front threat landscape dominated by the aggressive "The Gentlemen" Ransomware-as-a-Servi...

darkwebotx-pulsedarkweb-malware
Darkweb MalwareRead Now
Jun 12, 2026

The Gentlemen RaaS (Storm-2697) & AI Supply Chain (AMOS Stealer): OTX Pulse Analysis

Threat Summary Recent OTX pulses highlight a dual-threat landscape characterized by a sophisticated, high-volume Ransomware-as-a-Service (Ra...

darkwebotx-pulsedarkweb-malware
Darkweb MalwareRead Now