התחברות ל-baba News

חשבון אחד לאתר, לאייפון ולאנדרואיד — המנוי נשאר איתכם.

או קוד במייל

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

Search stories

הקלידו לפחות שני תווים. התוצאות מגיעות מכל המערכות ש-baba קורא.

to move · to open · esc to close

מסוף חי

התחברות ל-baba News

Sign in to keep asking. News Plus removes the daily limit.

או קוד במייל

לראות את התמונה המלאה

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

ביטחון14:20 · Aug 4

Massive Cyberattack Infects Hundreds of Thousands via Hugging Face Open-Source Libraries

מאת נבו טרבלסי
תורגם ותומצת מתוך Globes על ידי baba
The story · English

A major cybersecurity incident has shaken the developer community after researchers from Upwind revealed that dozens of popular open-source libraries on the Hugging Face platform, developed by a prolific contributor known as Keyv, were compromised with malicious code. Keyv's libraries have collectively been downloaded hundreds of millions of times worldwide by developers and organizations.

The attackers apparently hijacked Keyv's identity and used his access to inject malware into recent updates of his libraries. This malicious code was designed to steal usernames and passwords, raising serious concerns about a widespread supply chain attack. Estimates suggest that thousands, possibly tens of thousands, of organizations globally, along with hundreds of thousands of their users, could be exposed.

The scale of the breach involves approximately 1,500 libraries, potentially impacting 50% to 60% of organizations worldwide. The full extent of the damage is still unfolding. Security experts advise organizations and development teams to halt automatic updates and thoroughly verify the versions they have installed until the situation is clarified.

Dan Yahav, SVP Platforms at Upwind, explained that the attackers exploited a late-night window to insert unauthorized features and malicious code into many libraries without approval. Efforts to contact Keyv have so far been unsuccessful. Platforms hosting these libraries have begun removing the compromised packages to prevent further spread.

Gil Messing, head of global communications at Check Point, emphasized that these components are installed hundreds of millions of times monthly across thousands of systems and websites. The malware activates automatically upon installation, stealing access credentials including GitHub accounts, AWS keys, and secret management system passwords. Immediate steps include suspending automatic updates, auditing for affected packages, and monitoring for signs of compromise. Longer-term measures involve implementing delays before installing new packages to allow for security checks.

Read the original at Globes
פתיחת המסוף החי