Today's News: Sleepy Pickle Attack Exposes Critical Vulnerability in Machine Learning Supply Chain (November 16, 2025)
Discursive Podcast

Today’s News: Sleepy Pickle Attack Exposes Critical Vulnerability in Machine Learning Supply Chain (November 16, 2025)

2025-11-16
A team of researchers from Columbia University, Brown University, Purdue, Google, and Technion has uncovered a devastating supply chain attack vector that threatens the entire machine learning ecosystem. The "Sleepy Pickle" attack exploits how Python's pickle serialization format can execute arbitrary code when loading ML models - a vulnerability affecting nearly every major ML framework and potentially millions of models hosted on platforms like Hugging Face. The researchers demonstrated they could embed cryptocurrency miners, backdoors, and data...
View more
Comments (3)

More Episodes

All Episodes>>

Get this podcast on your phone, Free

Create Your Podcast In Minutes

  • Full-featured podcast site
  • Unlimited storage and bandwidth
  • Comprehensive podcast stats
  • Distribute to Apple Podcasts, Spotify, and more
  • Make money with your podcast
Get Started
It is Free