Crestvale Newsroom

Hugging Face breach turns datasets into attack path

6 min · 21. juli 2026
episode Hugging Face breach turns datasets into attack path cover

Beskrivelse

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A breach at Hugging Face is shifting attention away from models and toward something more fundamental: data ingestion as an attack surface. Attackers used a dataset to trigger code execution, then moved laterally and stole credentials, all at machine speed using autonomous agents. This matters because most security programs still treat ingestion pipelines, support systems, and internal tooling as low-risk infrastructure. That assumption is breaking down. From edge devices acting as credential harvesters to AI agents operating with legitimate access, the identity perimeter is expanding in ways many teams cannot yet see or control. We also cover SonicWall exploitation timelines, Neo's bet on AI agent governance, and a quiet but serious data leak through EY's support systems, along with key developments across supply chain attacks and SaaS-native malware. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Kommentarer

0

Vær den første til at kommentere

Tilmeld dig nu og bliv en del af Crestvale Newsroom-fællesskabet!

Kom i gang

1 måned kun 9 kr.

Derefter 99 kr. / måned · Opsig når som helst

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

Alle episoder

179 episoder

episode Hugging Face breach turns datasets into attack path cover

Hugging Face breach turns datasets into attack path

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A breach at Hugging Face is shifting attention away from models and toward something more fundamental: data ingestion as an attack surface. Attackers used a dataset to trigger code execution, then moved laterally and stole credentials, all at machine speed using autonomous agents. This matters because most security programs still treat ingestion pipelines, support systems, and internal tooling as low-risk infrastructure. That assumption is breaking down. From edge devices acting as credential harvesters to AI agents operating with legitimate access, the identity perimeter is expanding in ways many teams cannot yet see or control. We also cover SonicWall exploitation timelines, Neo's bet on AI agent governance, and a quiet but serious data leak through EY's support systems, along with key developments across supply chain attacks and SaaS-native malware. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

21. juli 20266 min
episode Spoofed OAuth client IDs blind Entra logs cover

Spoofed OAuth client IDs blind Entra logs

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] Identity signals are getting harder to trust. Attackers are now spoofing OAuth client IDs in Microsoft Entra ID, which means sign-in logs can misattribute the source of authentication attempts. At the same time, real-world attacks are shifting into places many teams do not continuously monitor, including browser runtime and third-party code. For security leaders, this changes how detection needs to work. Logs are no longer clean ground truth, and vendor trust cannot be static. Teams need to focus on behavior, anomaly patterns, and continuous visibility across identity systems and frontend execution. This episode also covers pre-disclosure exploitation of SonicWall SMA zero days, a browser-layer supply chain attack that led to a three million dollar loss, and AWS expanding Security Hub into a multi-cloud control plane. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

I går5 min
episode wp2shell pre-auth RCE: WordPress 7.0.2 out cover

wp2shell pre-auth RCE: WordPress 7.0.2 out

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A forced WordPress update, agentic browser risks, and a shift in supply chain attacks all point to the same problem: trust is being exploited faster than teams can validate it. For security and IT leaders, this is a change in where risk lives. Core platforms can be compromised without credentials, browser extensions can act with user privileges, and dependency updates can carry malicious code straight into CI. At the same time, ransomware operators are prioritizing identity access over traditional exploits. The result is a compressed window between exposure and impact. We also cover Microsoft's view on npm trust path attacks, new risks in AI browser agents, and why identity is again the primary entry point for ransomware. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

19. juli 20266 min
episode DigiCert breach linked to code-signing theft cover

DigiCert breach linked to code-signing theft

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] A breach tied to DigiCert has put code signing certificates in attacker hands, turning a core trust signal into a potential attack vector. At the same time, ransomware is now disrupting real world operations, and vendor risk is showing up in places many teams assume are safe. This episode breaks down why trust in signed software can no longer be assumed, how ransomware is shifting toward direct revenue disruption, and why identity and secrets platforms need deeper scrutiny. The common thread is control. Who has it, how it is verified, and where it quietly fails. We also cover CrowdStrike's move to absorb XM Cyber's technology, a ransomware driven production shutdown at Fairlife, and new concerns around Passwork's origins. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

18. juli 20265 min
episode Microsoft: AI agents need first-class identities cover

Microsoft: AI agents need first-class identities

Send us Fan Mail [https://www.buzzsprout.com/2602483/fan_mail/new] AI agents are no longer just assistants. They are becoming active participants inside systems, with the ability to take actions across tools and services. That shift is forcing a rethink of identity, access, and control. For security and IT leaders, this changes the threat model. Agents introduce new forms of privilege escalation, cross-system risk, and audit gaps that traditional identity frameworks were not built to handle. At the same time, regulatory pressure and real-world breaches are reinforcing that weak identity controls remain the easiest path for attackers. This episode also covers the CMMC audit pause and why liability remains, new developments tied to Scattered Spider, and Google's move into AI-driven app execution. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

17. juli 20266 min