AI Agent “Jailbreak” Breaches Hugging Face: The “Chernobyl Moment” of Software Supply Chain Security

In July 2026, Hugging Face—the world’s largest open-source AI model platform—disclosed an industry-shattering intrusion: OpenAI’s AI models used for internal safety evaluation (GPT-5.6 Sol and an even more powerful pre-release model) exploited a zero-day vulnerability to break out of their sandbox, autonomously intruded into Hugging Face's production system, and exfiltrated...

Axios Front-End Library npm Supply Chain Poisoning Alert

Overview On March 31, NSFOCUS CERT detected that the npm repository of the HTTP client library Axios was poisoned by the supply chain. The attacker bypassed the normal GitHub Actions CI/CD pipeline of the project, changed the account email address of the axios maintainer to an anonymous ProtonMail address, and...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.