BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: from_pretrained() to from_pwned(): Breaking HuggingF
 ace's\n   Trust\n   Tags: Intermediate | AppSec Village | Creator Talk/Pan
 el\n   When: Friday\, Aug 7\, 14:10 - 14:40 PDT\n   Where: LVCCW Level 1 H
 all 2 604 (Appsec Village) Main Stage - [1]Map\n\n   Description:\n\n   ug
 gingFace has become the GitHub of machine learning. Two million\n   models
 \, 15 million daily downloads. We discovered a critical RCE\n   (CVE-2026-
 4372) that compromises any machine loading a malicious\n   model. Add one 
 field to a model's config.json\, publish it on the Hub\,\n   and any stand
 ard from_pretrained() call is silently compromised. No\n   trust_remote_co
 de=True. No warnings. The one security boundary the\n   entire ML ecosyste
 m relies on\, bypassed completely.\n\n   The chain is three flaws: a gener
 ic setattr loop stamping every JSON\n   field onto the config object inclu
 ding private attributes\; a\n   sanitization gap protecting the public int
 erface but not the\n   underscore-prefixed internal equivalent\; and an un
 sandboxed kernel\n   loader executing arbitrary Python from any Hub repo. 
 One field\n   weaponizes all three.\n\n   We walk through the full attack 
 chain live. Model registries are the\n   new package registries\, facing t
 he same supply-chain threats that\n   broke the software world - with far 
 less mature defenses.\n\n   SpeakerBio:  Yotam Perkal\n\n   Yotam Perkal l
 eads security research at Pluto Security\, a\n   next-generation AI securi
 ty and governance platform designed to\n   protect the rapidly emerging ec
 osystem of AI builders\,\n   low-code/no-code tools\, and agentic applicat
 ions. His work focuses on\n   securing AI-native development environments 
 and building scalable\n   methods for detecting\, validating\, and mitigat
 ing risks in AI-driven\n   software workflows.\n\n   Previously\, Yotam le
 d the Threat Research team at Zscaler\, headed the\n   Vulnerability Resea
 rch team at Rezilion\, and held multiple roles\n   within PayPal’s secur
 ity organization across vulnerability\n   management\, threat intelligence
 \, and insider threat.\n\n   Yotam is an active participant in several cro
 ss-industry working\n   groups dealing with AI security\, vulnerability ma
 nagement\, and supply\n   chain security.\n\n   '\n\n   1. #LVCCW_Level1_H
 all2\n\n\n
DTEND:20260807T214000Z
DTSTART:20260807T211000Z
LOCATION:AppSec Village - LVCCW Level 1 Hall 2 604 (Appsec Village) Main St
 age
SUMMARY:from_pretrained() to from_pwned(): Breaking HuggingFace's Trust
END:VEVENT
END:VCALENDAR
