Zafran Labs has disclosed FaceHugger, multiple remote code execution flaws in Hugging Face's diffusers. The flaws let a malicious model silently run code on any machine that loads it, bypassing the trust_remote_code control. @0xgalz @ido__shani
Zafran's Threat Exposure Management Platform integrates with your security tools to reveal, remediate, and mitigate risk.
- Zafran Labs identified 2 critical vulns in Chainlit, a widely used AI framework. The flaws allow attackers to leak cloud API keys and steal sensitive files, as well as perform SSRF against servers hosting AI applications. @0xgalz @ido__shani
- BreakingWAF: Widespread WAF Bypass Discovered Impacting Nearly 40% of Fortune 100 companies. The Zafran Research Team has uncovered a critical misconfiguration in popular web application firewall (WAF) services including Akamai and Cloudflare zafran.io/resources/brea…
- Introducing Proactive Exposure Hunting, the latest enhancement to Zafran’s Threat Exposure Management Platform zafran.io/resources/intr…
- 🎬 Zafran Productions 🎬 We put your defenses on offense so you can identify and quickly defuse threat exploitation using your existing security controls. Make the first move with the world’s first Risk & Mitigation Platform #riskmitigation #RSAC2024 #cybersecurity

