<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Supply-Chain on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-supply-chain/</link><description>Recent content in Ai-Supply-Chain on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 12:46:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>CrowdStrike: Detecting SANDWORM_MODE AI Toolchain Supply Chain Attacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-denying-the-worm-detecting-sandworm-mode-and-the-emerging-cl/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-denying-the-worm-detecting-sandworm-mode-and-the-emerging-cl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The title signals research on an emerging attack class targeting AI/ML toolchains — no enrichment signals confirm active exploitation, so no immediate patch or audit action is warranted, but engineers building AI pipelines should read for architectural implications.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A CrowdStrike post explicitly framed around detection of a named technique (SANDWORM_MODE) likely contains TTPs or behavioral signatures worth converting into detections this quarter; no confirmed IOCs or KEV listing to justify an immediate sweep.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> AI toolchain supply chain attacks as a named, emerging category is useful framing for future policy and budget conversations, but without a confirmed breach or active campaign, no same-week leadership action is required.&lt;/li>
&lt;/ul></description></item><item><title>Hugging Face Breached by AI Agent; Internal Datasets and Credentials Exposed</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-world-s-largest-ai-model-repository-hugging-face-breached-by/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-world-s-largest-ai-model-repository-hugging-face-breached-by/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Hugging Face is widely embedded in ML pipelines via API tokens and model downloads — rotate all Hugging Face access tokens in your CI/CD and development environments immediately and audit secrets stores for any exposed HF credentials.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active breach at a broadly used AI platform with confirmed credential exposure; sweep secrets managers and env-var configs for Hugging Face tokens, hunt for anomalous outbound calls to HF APIs since last week, and flag any service accounts with HF integration for review.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether the organization uses Hugging Face for model hosting, inference APIs, or dataset storage, then request a vendor incident report detailing scope; brief leadership on the novel autonomous-AI-agent attack vector, which is likely to generate board-level questions.&lt;/li>
&lt;/ul></description></item></channel></rss>