{"id":6644,"date":"2025-09-04T10:03:35","date_gmt":"2025-09-04T10:03:35","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/new-namespace-reuse-vulnerability-allows-remote-code-execution-in-microsoft-azure-ai-google-vertex-ai-and-hugging-face\/"},"modified":"2025-09-04T10:03:35","modified_gmt":"2025-09-04T10:03:35","slug":"new-namespace-reuse-vulnerability-allows-remote-code-execution-in-microsoft-azure-ai-google-vertex-ai-and-hugging-face","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/04\/new-namespace-reuse-vulnerability-allows-remote-code-execution-in-microsoft-azure-ai-google-vertex-ai-and-hugging-face\/","title":{"rendered":"New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face"},"content":{"rendered":"<p>    New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source projects.<\/p>\n<p>The newly discovered attack method, termed \u201cModel Namespace Reuse,\u201d exploits a fundamental flaw in how AI platforms manage and trust model identifiers within the Hugging Face ecosystem.<\/p>\n<p>The vulnerability stems from Hugging Face\u2019s namespace management system, where models are identified using a two-part naming convention: Author\/ModelName.<\/p>\n<p>When organizations or authors delete their accounts from Hugging Face, their unique namespaces return to an available pool rather than becoming permanently reserved.<\/p>\n<p>This creates an opportunity for malicious actors to register previously used namespaces and upload compromised models under trusted names, potentially affecting any system that references models by name alone.<\/p>\n<p>Palo Alto Networks analysts <a href=\"https:\/\/unit42.paloaltonetworks.com\/model-namespace-reuse\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this supply chain attack vector during an extensive investigation of AI platform security practices.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgw2xC1dR9vXG-g4vkCFwRvKoZqs3ZlyV7iDapi4N8LNqc_H0V-08CKp7Krr0n2pnKlSAhvMpiY9UHk5v2gM_3hz-iGX8myGAOQ1fVHgPCpu_Cth0L3T6Xz_bEkD4KaHTxLeKDLCApLxzUPwezSSKPXu-CTVWMwX3GjvFKFXXAkJqh-fcodRZHvsS8Xuu4\/s16000\/High-level%2520view%2520of%2520the%2520attack%2520vector%2520flow%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">High-level view of the attack vector flow (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>The research revealed that the vulnerability affects not only direct integrations with <a href=\"https:\/\/cybersecuritynews.com\/malicious-ml-models-detected-on-hugging-face\/\" target=\"_blank\" rel=\"noreferrer noopener\">Hugging Face<\/a> but also extends to major cloud AI services that incorporate Hugging Face models into their catalogs.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjHVy3U4xlHfenUh9jmAqbfpNLJ0-swUJu6mtBQAjEvU6MFe4Wp-bIrZM7ZWi6HATfJy01xZOGxFXI_yxZ70fkDuAJUEG3alNFdYM773XQAXwOYd1VWJaUpwcPY-vrC3Av_aFnxc90MHSyzLelDbc8CwmxOCKtiekid2UMhMMtC7pT7S1vfM9n1MfMWK-0\/s16000\/Variety%2520of%2520Hugging%2520Face%2520models%2520in%2520AI%2520Foundry%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Variety of Hugging Face models in AI Foundry (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>The attack\u2019s scope is particularly concerning given the widespread adoption of AI models across enterprise environments and the implicit trust placed in model naming conventions.<\/p>\n<p>The attack mechanism operates through two primary scenarios. In the first, when a model author\u2019s account is deleted, the namespace becomes immediately available for re-registration.<\/p>\n<p>The second scenario involves ownership transfers where models are moved to new organizations, followed by deletion of the original author account.<\/p>\n<p>In both cases, malicious actors can exploit the namespace reuse to substitute legitimate models with compromised versions containing malicious payloads.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-technical-implementation-and-attack-vectors\"><strong>Technical Implementation and Attack Vectors<\/strong><\/h2>\n<p>The researchers demonstrated the vulnerability\u2019s practical impact through controlled proof-of-concept attacks against Google Vertex AI and Microsoft Azure AI Foundry.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvhpavFO_2Yd67WnC7l86BGDTIlOgIU49NCscZj3Ddidgvmdl6sZeu71fU3YFvYtRD3s6956LyxSPD0CFEWEkUmdefT1g0r6FZUx5rOtqGsyUhpDlcRBSWaszrK6LU3sR7_FuIsL9e7HX8DEM25DwpDMwkD4MU0myxrbvOFkWP0r4qo4MlOBlLpQXlAMY\/s16000\/Deploying%2520a%2520model%2520from%2520Hugging%2520Face%2520to%2520Vertex%2520AI%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Deploying a model from Hugging Face to Vertex AI (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>In their testing, they successfully registered abandoned namespaces and uploaded models embedded with reverse shell payloads.<\/p>\n<p>The malicious code executed automatically when cloud platforms deployed these seemingly <a href=\"https:\/\/cybersecuritynews.com\/lazarus-hackers-altering-legitimate-software-packages\/\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate models<\/a>, granting attackers access to underlying infrastructure.<\/p>\n<pre class=\"wp-block-code\"><code>from transformers import AutoTokenizer, AutoModelForCausalLM\n\n# Vulnerable code pattern found in thousands of repositories\ntokenizer = AutoTokenizer.from_pretrained(\"AIOrg\/Translator_v1\")\nmodel = AutoModelForCausalLM.from_pretrained(\"AIOrg\/Translator_v1\")<\/code><\/pre>\n<p>The attack\u2019s effectiveness lies in its exploitation of automated deployment processes. When platforms like Vertex AI\u2019s Model Garden or Azure AI Foundry\u2019s Model Catalog reference models by name, they inadvertently create persistent attack surfaces.<\/p>\n<p>The researchers documented gaining access to dedicated containers with elevated permissions within <a href=\"https:\/\/cybersecuritynews.com\/google-cloud-and-cloudflare-outages\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Cloud<\/a> Platform and Azure environments, demonstrating the severity of potential breaches.<\/p>\n<p>Organizations can mitigate this risk through version pinning, implementing the revision parameter to lock models to specific commits, and establishing controlled storage environments for critical AI assets.<\/p>\n<p>The discovery underscores the urgent need for comprehensive <a href=\"https:\/\/cybersecuritynews.com\/top-security-frameworks\/\" target=\"_blank\" rel=\"noreferrer noopener\">security frameworks<\/a> addressing AI supply chain vulnerabilities as organizations increasingly integrate machine learning capabilities into production systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-namespace-reuse-vulnerability\/\">New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-namespace-reuse-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Namespace Reuse Vulnerability Allows Remote Code Execution in Microsoft Azure AI, Google Vertex AI, and Hugging Face Cybersecurity researchers have uncovered a critical vulnerability in the artificial intelligence supply chain that enables attackers to achieve remote code execution across major cloud platforms including Microsoft Azure AI Foundry, Google Vertex AI, and thousands of open-source [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6644","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6644"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6644"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6644\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}