Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:huggingface_blog, report:the_hacker_news, report:trail_of_bits
tags: report:huggingface_blog, report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
tags: report:the_hacker_news
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Designing the hf CLI as an agent-optimized way to work with the Hub Designing the hf CLI as an agent-optimized way to work with the Hub Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizations Community
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough
How an Agent Built a 3D Paris Gallery by Chaining Two Hugging Face Spaces How an Agent Built a 3D Paris Gallery by Chaining Two Hugging Face Spaces Hugging Face Models Datasets Spaces Buckets new Docs Enterprise Pricing Website Tasks HuggingChat Collections Languages Organizatio
Introducing Patch the Planet What happens when you clear dozens of Trail of Bits engineers’ schedules, pair them with every open-source maintainer they can contact, and unleash the latest frontier models like GPT-5.5-Cyber on critical open-source targets? Thanks to our partnersh
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact"
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agen
Deduped connector weight from graph context.