Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face

New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face

Posted on September 4, 2025September 4, 2025 By CWS

Cybersecurity researchers have uncovered a important vulnerability within the synthetic intelligence provide chain that permits attackers to realize distant code execution throughout main cloud platforms together with Microsoft Azure AI Foundry, Google Vertex AI, and 1000’s of open-source tasks.

The newly found assault technique, termed “Mannequin Namespace Reuse,” exploits a basic flaw in how AI platforms handle and belief mannequin identifiers throughout the Hugging Face ecosystem.

The vulnerability stems from Hugging Face’s namespace administration system, the place fashions are recognized utilizing a two-part naming conference: Creator/ModelName.

When organizations or authors delete their accounts from Hugging Face, their distinctive namespaces return to an out there pool moderately than turning into completely reserved.

This creates a possibility for malicious actors to register beforehand used namespaces and add compromised fashions beneath trusted names, doubtlessly affecting any system that references fashions by title alone.

Palo Alto Networks analysts recognized this provide chain assault vector throughout an intensive investigation of AI platform safety practices.

Excessive-level view of the assault vector stream (Supply – Palo Alto Networks)

The analysis revealed that the vulnerability impacts not solely direct integrations with Hugging Face but additionally extends to main cloud AI providers that incorporate Hugging Face fashions into their catalogs.

Number of Hugging Face fashions in AI Foundry (Supply – Palo Alto Networks)

The assault’s scope is especially regarding given the widespread adoption of AI fashions throughout enterprise environments and the implicit belief positioned in mannequin naming conventions.

The assault mechanism operates by way of two major eventualities. Within the first, when a mannequin creator’s account is deleted, the namespace turns into instantly out there for re-registration.

The second situation includes possession transfers the place fashions are moved to new organizations, adopted by deletion of the unique creator account.

In each instances, malicious actors can exploit the namespace reuse to substitute authentic fashions with compromised variations containing malicious payloads.

Technical Implementation and Assault Vectors

The researchers demonstrated the vulnerability’s sensible affect by way of managed proof-of-concept assaults towards Google Vertex AI and Microsoft Azure AI Foundry.

Deploying a mannequin from Hugging Face to Vertex AI (Supply – Palo Alto Networks)

Of their testing, they efficiently registered deserted namespaces and uploaded fashions embedded with reverse shell payloads.

The malicious code executed routinely when cloud platforms deployed these seemingly authentic fashions, granting attackers entry to underlying infrastructure.

from transformers import AutoTokenizer, AutoModelForCausalLM

# Susceptible code sample present in 1000’s of repositories
tokenizer = AutoTokenizer.from_pretrained(“AIOrg/Translator_v1”)
mannequin = AutoModelForCausalLM.from_pretrained(“AIOrg/Translator_v1”)

The assault’s effectiveness lies in its exploitation of automated deployment processes. When platforms like Vertex AI’s Mannequin Backyard or Azure AI Foundry’s Mannequin Catalog reference fashions by title, they inadvertently create persistent assault surfaces.

The researchers documented having access to devoted containers with elevated permissions inside Google Cloud Platform and Azure environments, demonstrating the severity of potential breaches.

Organizations can mitigate this threat by way of model pinning, implementing the revision parameter to lock fashions to particular commits, and establishing managed storage environments for important AI property.

The invention underscores the pressing want for complete safety frameworks addressing AI provide chain vulnerabilities as organizations more and more combine machine studying capabilities into manufacturing techniques.

Enhance your SOC and assist your crew defend your small business with free top-notch risk intelligence: Request TI Lookup Premium Trial.

Cyber Security News Tags:Azure, Code, Execution, Face, Google, Hugging, Microsoft, Namespace, Remote, Reuse, Vertex, Vulnerability

Post navigation

Previous Post: Tidal Cyber Raises $10 Million for CTI and Adversary Behavior Platform
Next Post: Threat Actors Attack PayPal Users in New Account Profile Set up Scam

Related Posts

Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats Cyber Security News
Preventing OAuth Consent Abuse in Entra ID Preventing OAuth Consent Abuse in Entra ID Cyber Security News
8000+ SmarterMail Hosts Vulnerable to RCE Attack 8000+ SmarterMail Hosts Vulnerable to RCE Attack Cyber Security News
Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices Google Sued BadBox 2.0 Malware Botnet Operators That Infects 10 Million+ Devices Cyber Security News
Cyberattack on Novo Nordisk Exposes Medical and AI Data Cyberattack on Novo Nordisk Exposes Medical and AI Data Cyber Security News
First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code First-ever AI-powered ‘MalTerminal’ Malware uses OpenAI GPT-4 to Generate Ransomware Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark