Hugging Face API calls as exfiltration infrastructure. Legitimate endpoint, expected traffic pattern for ML workloads, nearly invisible in standard monitoring unless you know what you’re looking for. The defender callout is the most actionable thing here: unexpected huggingface[.]co/api calls from non-ML processes are the tell. That’s a detection rule worth adding today.
Big news for Blue Team nerds
That nerd who released those Microsoft 0days has created two new repos on GitHub with spooky sounding names indicating they will be releasing two new Windows 0days.
Very cool
https://t.co/VaWFtW5lFi