Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
What's Hot

23 Aldi Dinners Under $10 Your Family Won’t Complain About

June 2, 2026

What do SMEs think is the best business bank account? – survey

June 2, 2026

Daloopa Raises $47M to Make AI-Driven Investment Research Reliable and Auditable – AlleyWatch

June 2, 2026
Facebook Twitter Instagram
Tuesday, June 2
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Business CircleBusiness Circle
  • Home
  • AI News
  • Startups
  • Markets
  • Finances
  • Technology
  • More
    • Human Resource
    • Marketing & Sales
    • SMEs
    • Lifestyle
    • Trading & Stock Market
Subscribe
Business CircleBusiness Circle
Home » Python libraries used in top AI and ML tools hacked – Nvidia, Salesforce and other libraries all at risk
Technology

Python libraries used in top AI and ML tools hacked – Nvidia, Salesforce and other libraries all at risk

Business Circle TeamBy Business Circle TeamJanuary 14, 2026Updated:January 14, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Python libraries used in top AI and ML tools hacked – Nvidia, Salesforce and other libraries all at risk
Share
Facebook Twitter LinkedIn Pinterest Email



  • Palo Alto discovered essential flaws in AI/ML libraries NeMo, Uni2TS, and FlexTok
  • Vulnerabilities allowed arbitrary code execution by way of malicious mannequin metadata
  • All patched by mid-2025; no exploitation noticed as of December 2025

Safety researchers from Palo Alto Networks have found vulnerabilities utilized in some high Synthetic Intelligence (AI) and machine Studying (ML) instruments which, if abused, may enable risk actors to execute malicious code on course endpoints, remotely.

In a safety advisory, the researchers mentioned that round April 2025, they found bugs in three open supply Python libraries revealed by Apple, Salesforce, and NVIDIA, on their GitHub repositories.

The libraries are known as NeMo, Uni2TS, and FlexTok. NeMo is a PyTorch-based framework for analysis, Uni2TS a PyTorch library for analysis utilized by Salesforce’s Morai, and FlexTok is a Python-based framework for analysis, enabling AL and ML fashions to course of photos. Cumulatively, they’ve greater than 10 million downloads on HuggingFace (a platform that hosts open-source AI fashions and different instruments).


Chances are you’ll like

Bugs fastened

“The vulnerabilities stem from libraries utilizing metadata to configure advanced fashions and pipelines, the place a shared third-party library instantiates courses utilizing this metadata,” Palo Alto defined in its advisory.

“Susceptible variations of those libraries merely execute the supplied information as code. This permits an attacker to embed arbitrary code in mannequin metadata, which might routinely execute when weak libraries load these modified fashions.”

All three builders have been notified in April 2025, and by the top of July, all have been fastened. NVIDIA issued CVE-2025-23304 and gave it a excessive severity ranking (7.8/10) and launched a repair in NeMo 2.3.2. FlexTok up to date its code in June 2025, whereas Salesforce issued CVE-2026-22584, gave it a essential ranking (9.8/10), and stuck it in July 2025.

Palo Alto says that as of December 2025, there isn’t any proof that these vulnerabilities are being abused within the wild. The entire bugs have been found by the corporate’s Prisma AIRS instrument.

Signal as much as the TechRadar Professional e-newsletter to get all the highest information, opinion, options and steerage your small business must succeed!


Best antivirus software header

One of the best antivirus for all budgets

Our high picks, based mostly on real-world testing and comparisons

Comply with TechRadar on Google Information and add us as a most well-liked supply to get our skilled information, critiques, and opinion in your feeds. Be sure that to click on the Comply with button!

And naturally you may as well comply with TechRadar on TikTok for information, critiques, unboxings in video type, and get common updates from us on WhatsApp too.





Source link

Hacked Libraries NVIDIA Python risk Salesforce Tools top
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Business Circle Team
Business Circle Team
  • Website

Related Posts

From code-first to intent-first: Microsoft Build 2026 could be the end of programming as we know it

June 2, 2026

Google’s first new smart speaker in six years might finally have a release date

June 2, 2026

Russia’s Military Hackers Targeted Home Routers Across 23 States. Here’s What to Do

June 2, 2026

Anker’s 250W desktop charging station cuts clutter, now $50 off

June 1, 2026
LATEST UPDATES

23 Aldi Dinners Under $10 Your Family Won’t Complain About

June 2, 2026

What do SMEs think is the best business bank account? – survey

June 2, 2026

Daloopa Raises $47M to Make AI-Driven Investment Research Reliable and Auditable – AlleyWatch

June 2, 2026

Google Is Using AI to Change the Rules of the Internet

June 2, 2026

Agentic AI and Content & Messaging: What Revenue Leaders Need to Know, Act On, and Watch Out For

June 2, 2026

From code-first to intent-first: Microsoft Build 2026 could be the end of programming as we know it

June 2, 2026

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Business, Finance and Market Growth News Site

Important Pages
  • Advertise with us
  • Submit Articles
  • About us
  • Contact us
Recent Posts
  • 23 Aldi Dinners Under $10 Your Family Won’t Complain About
  • What do SMEs think is the best business bank account? – survey
  • Daloopa Raises $47M to Make AI-Driven Investment Research Reliable and Auditable – AlleyWatch
© 2026 BusinessCircle.co
  • Privacy Policy
  • Terms and Conditions
  • Cookie Privacy Policy
  • Disclaimer
  • DMCA

Type above and press Enter to search. Press Esc to cancel.