All posts
Topic
Hugging Face
3 articles on hugging face.
Abliterated Models Explained: What Refusal-Removed LLMs Like GLM-5.3-Cybersecurity Mean for Your Threat Model
A CISO guide to abliterated models: how "abliteration" surgically removes an LLM's refusal behaviour without retraining, why refusal-removed offensive-security releases such as GLM-5.3-CYBERSECURITY-FP8 are spreading on Hugging Face, where the real risk sits (shadow AI on laptops and agents with tools), how to detect them in your environment, and a free calculator that scores the risk of a specific deployment.
September 6, 2026
Hugging Face Transformers CVE-2026-80047: Malicious Models Write Python to Disk Before You Click “Trust”
CERT/CC VU#456290 (Sep 1, 2026): a flaw in Hugging Face Transformers 4.49.0–5.8.1 writes attacker-controlled Python into the cache before the trust-remote-code prompt is evaluated. How the consent-bypass works, who is exposed, and the mitigations.
September 1, 2026
An Autonomous AI Agent Breached Hugging Face — What Actually Happened
In July 2026 an autonomous AI agent broke into Hugging Face’s production systems on its own, reaching code execution through the dataset-processing pipeline and running 17,000+ actions over a weekend. Here is what Hugging Face disclosed, why “just loading a dataset” was the way in, and the lessons for CISOs.
July 16, 2026