The security assumption every AI team gets wrong: "As long as trust_remote_code=False is set, we are safe." ❌
We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control.
A thread on how a routine model load turns into complete environment compromise 👇
1/3 🔍 The Exploit & ScaleBy abusing model configuration fields, an attacker can embed a malicious payload inside a configuration file. It executes arbitrary code even with remote code disabled.
The affected versions were downloaded over 232M times while live.
2/3 🚨 The RiskSuccessful exploitation means full environment compromise—exposing cloud credentials, API keys, source code, and proprietary datasets.
Impacts Transformers versions 4.56.0 through 5.2.x.
3/3 🛡️ Remediation• Upgrade to version 5.3.0 immediately. • Audit previously downloaded model configurations. • Move beyond checkbox security—static ecosystem flags aren't enough.
Kudos to the Hugging Face team for the quick patch collaboration.
👇 Full technical breakdown link in the replies!
Last time, we published ClaudeSec - our security-first hub for the Claude ecosystem.
Now, CopilotSec is officially LIVE.
A new community knowledge hub for security of the Microsoft AI ecosystem, powered by Pluto.
Ever wanted a single place to understand what Microsoft AI connectors actually do?
Wondered which ones are high-risk?
Trying to figure out how to securely deploy Copilot Studio, agents, MCP servers, or AI workflows in production?
That’s exactly why we built CopilotSec.
Inside you’ll find:
1,718 Microsoft ecosystem connectors mapped by capability and riskSecurity guides for Copilot Studio and Microsoft AI deploymentsCurated security updates and findings that actually matter to security teams
Built for practitioners. Open to everyone.
Give it a try and let us know what you think!
Link in the first comment 👇
Someone finally built a security database for the Claude ecosystem.
It's called ClaudeSec, and Pluto Security just launched it for free.
Here's the gap it fills => 53 new Claude connectors shipped in the last 30 days. Your security team reviewed zero of them. Someone on your team authorized at least one.
Most enterprises adopting Claude have no process to evaluate connectors before authorization.
ClaudeSec tracks 384 connectors. 103 flagged high risk. That's around 27% of the ecosystem.
Every entry shows:
→ What capabilities the connector actually has
→ What tools it exposes to the model
→ Why it's rated risky
→ Source-code findings where they did the review
Security guides are live for Claude Managed Agents and Cowork. Real configuration - policies, hooks, permission scopes, allow/deny rules.
The Cowork guide is the one Enterprise teams need to read first.
Cowork runs code, browses with real user sessions, and operates unattended. The architecture is solid, gVisor sandbox, layered network controls. But Cowork activity is excluded from Audit Logs, the Compliance API, and Data Exports. All plan tiers. Including Enterprise.
Your visibility tools don't see what Cowork is doing.
Claude Code and Office Agents guides ship next.
The curated news feed flags CVEs and incidents as they happen. The window between a connector being compromised and detection is roughly 3 hours. The feed is built around that window.
Read here:
ClaudeSec: claudesec.pluto.security
Launch blog: pluto.security/blog/introduci…
Cowork teardown: pluto.security/blog/claude-co…
Thanks to @pluto_security for supporting this post.
@sama@VampireGurlAI Big move. Most enterprises are still figuring out how to govern the AI they already have. Now they need to secure what's securing them too.
@AnthropicAI Opening up bug bounties is the right call. Finding the vulnerability is step one. The harder question is what happens in production before anyone finds it.
ClaudeSec is officially LIVE!
Meet the new security-first hub for the Claude ecosystem, powered by @pluto_security.
❓Always yearned for a unified search of all existing extensions?
❓Ever wondered what ones are flagged as high-risk?
❓Dreaming of knowing how to deploy safely with Claude?
All of this (and more) is now waiting for you on our new planet.
Give it a go and let us know in the comments what you thought!
Link in the first comment.
Our research team disclosed CVE-2026-33032, a critical CVSS 9.8 vulnerability in nginx-ui that exposed over 500K users to full server takeover through a single unauthenticated request. No credentials. No exploit chain. Actively exploited in the wild.
The root cause: MCP endpoints that inherit an application's full capabilities but skip its security controls entirely.
The pattern is clear - and it's only getting more common as agentic workflows connect deeper into enterprise workspace infrastructure.
Most security teams have no visibility into what MCP servers are running in their environment, no inventory of the endpoints they're exposing, and no way to enforce it.
Full breakdown → lnkd.in/dmbkkQAp
As covered by The Hacker News → lnkd.in/gWTZt4e4
80 Followers 76 FollowingPostdoctoral composite material scientist.
I’m building a local first, modular productivity app.
Join the waitlist;
https://t.co/ueFYXm5cV1
@exsutapp
149 Followers 157 FollowingDev building things. Sharing experience.
https://t.co/hxTVT8j8AD
Some of my apps:
- https://t.co/k2L6Rmoz8f
- https://t.co/Fteb9QGyD8
- https://t.co/lQ8Aymajjv
36 Followers 151 FollowingNexus Digtial Solutions is here! Debuting our first comercial release and please to do so: 206 CIS controlls with FULL ROLLBACK. #Linux #Terminal #Rollback
80 Followers 76 FollowingPostdoctoral composite material scientist.
I’m building a local first, modular productivity app.
Join the waitlist;
https://t.co/ueFYXm5cV1
@exsutapp
149 Followers 157 FollowingDev building things. Sharing experience.
https://t.co/hxTVT8j8AD
Some of my apps:
- https://t.co/k2L6Rmoz8f
- https://t.co/Fteb9QGyD8
- https://t.co/lQ8Aymajjv
815 Followers 642 Following👪 Family Man| Software Engg. Lead with DevOps, Python, Backend & AI Builder experience. Stories on Tech & Job Market also love Cricket, Taxation & Geo Politics
36 Followers 151 FollowingNexus Digtial Solutions is here! Debuting our first comercial release and please to do so: 206 CIS controlls with FULL ROLLBACK. #Linux #Terminal #Rollback
128 Followers 132 FollowingBuilding custom AI solutions for SMBs. Integrating intelligent systems with business operations to automate, gain insights, and scale faster in DFW & Nashville.
34 Followers 248 FollowingVibe Coding is my passion. Futebol é a segunda paixão.
Gradientes, glasmorfismo, tailwind.
Se o contexto da ia acabar, eu alucino junto com ela.
10 Followers 146 FollowingTrying my hand at indie hacking, startup, and building in public. Besides learning sciences, I dabble in AGI and ASI research.
3K Followers 3K FollowingFast ≠ sloppy. Correctness scales.
AI builds apps. We make them reliable.
SaaSEasy
Structured systems. Fewer bugs. Real control
Web • Mobile • Desktop
25+ yrs
14 Followers 182 FollowingSenior Full-stack dev 🇨🇴. Hago tooling con IA para medios. Building @snapfail in public (para los que no leemos stack traces 😅). Fail, fix, share.
59 Followers 95 FollowingSoftware engineer into product engineering, AI, and bleeding-edge tech stacks. Building products that turn ideas into real experiences.
186 Followers 222 FollowingCreator of LazyPredict (1.17M+ downloads). 13+ yrs in ML. Building open-source AI tools & learning platforms at https://t.co/Uh5TufbcN2. Shipping in public.