First reported · updated · 3 reports medium.com
Analysis · latest
First reported barhum.ai
The Hidden Risks of Downloading and Running Open-Source LLMs Locally: Model Formats, Supply-Chain Attacks, and EDR Blind Spots
A Barhum.ai report maps the security attack surface of running open-source LLMs locally, arguing model files are executable artifacts: Python pickle formats (.pt/.pth/.bin) permit arbitrary code execution by design, PickleScan has been bypassed by zero-day vulnerabilities, and inference engines like Ollama have accumulated multiple critical CVEs. It notes CVE-2025-32434 (CVSS 9.3) showed torch.load() with weights_only=True was still exploitable, and highlights that EDR tools are architecturally blind to model-layer threats. Details →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector