Innovation Hub

AI Threat Landscape Report 2025

DeepSeek-R1 Architecture

Summary HiddenLayer’s previous blog post on DeepSeek-R1 highlighted security concerns identified during analysis and urged caution on its deployment. This blog takes that into further consideration, combining it with the principles of ShadowGenes to identify possible unsanctioned deployment of the model within an organization’s environment. For a more detailed technical analysis, join us here as […]

Analysing DeepSeek-R1’s Architecture

Summary HiddenLayer’s previous blog post on DeepSeek-R1 highlighted security concerns identified during analysis and urged caution on its deployment. This blog takes that into further consideration, combining it with the principles of ShadowGenes as a means of identifying possible unsanctioned deployment of the model within an organization’s environment. Join us as we delve into the […]

Reports and Guides

AI Threat Landscape Report 2025

Download your copy of HiddenLayer's 2025 AI Threat Landscape Report to learn more about evolving AI vulnerabilities and how securing AI can fuel your organization's innovation

Reports & Guides

AI Threat Landscape Report 2025

HiddenLayer Named a Cool Vendor in AI Security

A Step-By-Step Guide for CISOS

SAI Security Advisory

CVE-2024-0129

NVIDIA NeMo Vulnerability Report

Unsafe extraction of NeMo archive leading to arbitrary file write CVE Number CVE-2024-0129 Summary The _unpack_nemo_file function used by the SaveRestoreConnector class for model loading uses tarfile.extractall() in an unsafe way which can lead to an arbitrary file write when a model is loaded. Products Impacted This vulnerability is present in Nvidia NeMo versions prior to r2.0.0rc0. CVSS Score: 6.3 AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L […]

CVE-2024-24590

Pickle Load on Artifact Get Leading to Code Execution

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24591

Path Traversal on File Download Leading to Arbitrary Write

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24592

Improper Auth Leading to Arbitrary Read-Write Access

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

CVE-2024-24593

Cross-site Request Forgery in ClearML Server

Following responsible disclosure practices, the vulnerabilities referenced in this blog were disclosed to ClearML before publishing. We would like to thank their team for their efforts in working with us to resolve the issues well within the 90-day window. This demonstrates that responsible disclosure allows for a good working relationship between security teams and product […]

HiddenLayer in the News

Security for AI Platform Expansion: Introducing Automated Red Teaming for AI

Austin, TX — November 20, 2024 — HiddenLayer, a leader in security for AI solutions, today announced the launch of its Automated Red Teaming solution for artificial intelligence, a transformative tool that enables security teams to rapidly and thoroughly assess generative AI system vulnerabilities. The addition of this new product extends HiddenLayer’s AISec platform capabilities […]

HiddenLayer Recognized as a Gartner Cool Vendor for AI Security in 2024

Austin, TX – October 30, 2024 – HiddenLayer, a leader in security for AI solutions, is honored to be recognized as a Cool Vendor for AI Security in Gartner’s 2024 report. This prestigious distinction highlights HiddenLayer’s innovative approaches to safeguarding artificial intelligence models, data, and workflows against a rapidly evolving threat landscape. HiddenLayer’s proactive solutions […]

HiddenLayer Announces New Features to Safeguard Enterprise AI Models with Improved Risk Detection

Austin, TX – October 8, 2024 – HiddenLayer today announced the launch of several new features to its AISec Platform and Model Scanner, designed to enhance risk detection, scalability, and operational control for enterprises deploying AI at scale. As the pace of AI adoption accelerates, so do the threats targeting these systems, necessitating security measures […]