#supply-chain
-
AI Bill of Materials Tools: AIBOM Formats and Generators
Two AIBOM standards (CycloneDX ML-BOM, SPDX 3.0 AI profile), one free OWASP generator, and how to pick a tool without buying shelfware.
-
ML Model CVE Tracking: How to Monitor Your AI Stack
How to track CVEs across ML frameworks, inference servers, and model artifacts, and what to do when a vendor disputes the advisory anyway.
-
Malicious Model File Detection: Auditing ML Models
Pickle serialization flaws, PickleScan bypass CVEs, and a practical detection stack for teams pulling models from public repositories like Hugging Face.
-
Hugging Face Model Supply Chain Risk: Pickle Backdoors
How Hugging Face model supply chain risk works: pickle backdoors, the Transformers RCE CVE cluster, why the Hub scanner misses them, and what cuts risk.
-
TensorFlow Security Vulnerabilities 2026: CVEs and Supply Chain
A breakdown of the top TensorFlow security vulnerabilities in 2026: CVE-2025-49655, CVE-2025-12058, DoS flaws in 2.18.0, and supply chain risk.