Researchers disclosed multiple serious security issues affecting AI tooling, led by critical vulnerabilities in Ollama that can expose systems and data. Wiz reported CVE-2024-37032 (Probllama), an easy-to-exploit remote code execution flaw caused by improper validation of model manifests from private registries, allowing path traversal, arbitrary file read/write, and code execution—especially in Docker deployments running as root and listening on 0.0.0.0 without authentication. A separate disclosure described CVE-2026-7482 (Bleeding Llama), which can leak heap memory through Ollama’s GGUF model creation and quantization workflow and exfiltrate the resulting artifact via the /api/push endpoint, while CVE-2026-42248 and CVE-2026-42249 affect the Windows updater and can be chained for persistent code execution through missing signature checks and unsafe ETag handling.
The disclosures landed alongside a software supply chain incident on Hugging Face, where a malicious repository impersonating OpenAI’s Privacy Filter reportedly climbed to the platform’s trending list and drew more than 240,000 downloads before removal. The fake package used cloned documentation and likely inflated engagement metrics to appear legitimate, then delivered a multi-stage Windows infection that gained SYSTEM-level persistence, disabled security controls, and deployed the Rust-based stealer sefirah to collect wallet data, Discord tokens, developer credentials, browser secrets, screenshots, and sensitive files for exfiltration. Together, the incidents show how exposed AI infrastructure, weak authentication defaults, and trust in popular model and code repositories are creating high-impact attack paths; defenders were urged to upgrade Ollama to fixed versions, avoid direct internet exposure, use authenticated reverse proxies, and scrutinize third-party AI packages before deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Analysis of the campaign found infrastructure overlaps with prior ValleyRAT/Winos 4.0 activity associated with the Silver Fox threat group. The findings suggested an expansion of software supply chain attacks into the AI and machine learning ecosystem.
The fake repository was found to deploy a multi-stage Windows infection that established SYSTEM-level persistence, disabled security controls, and installed a Rust-based stealer called “sefirah.” The malware stole wallet data, Discord tokens, developer credentials, browser secrets, screenshots, and sensitive files for exfiltration to attacker-controlled infrastructure.
A malicious Hugging Face repository impersonating OpenAI’s Privacy Filter reportedly reached the platform’s trending list and amassed more than 240,000 downloads before removal. The project used cloned documentation and likely inflated engagement metrics to appear legitimate.
Striga and CERT Polska disclosed CVE-2026-42248 and CVE-2026-42249 affecting the Ollama Windows desktop updater, where missing signature verification and unsafe ETag handling could be chained for persistent code execution via the Startup folder. The issues were reported as still unpatched more than 90 days after disclosure, and users were advised to disable auto-updates and update manually.
A vendor fix was made available for CVE-2026-7482, with guidance to upgrade to at least Ollama v0.23.2; versions below 0.17.1 were described as vulnerable. The disclosure noted that widespread unauthenticated internet exposure increased the flaw’s potential impact.
Researchers disclosed CVE-2026-7482, nicknamed “Bleeding Llama,” a flaw in Ollama’s GGUF model creation and quantization pipeline that enables unauthenticated heap memory exfiltration and artifact exfiltration via the /api/push endpoint. The issue could reportedly be exploited in as few as three HTTP requests.
Wiz published technical details for CVE-2024-37032 and reported finding more than 1,000 internet-exposed Ollama servers, many without authentication and hosting numerous models, including private ones. The disclosure also recommended avoiding direct internet exposure and using authenticated reverse proxies.
After responsible disclosure, Ollama quickly fixed the Probllama vulnerability and advised users to upgrade to version 0.1.34 or newer. The risk was especially severe for Docker deployments running as root and listening on 0.0.0.0 by default.
Wiz Research identified CVE-2024-37032, dubbed “Probllama,” an input-validation flaw in Ollama’s model manifest handling that could lead to path traversal, arbitrary file read/write, and remote code execution. The issue was responsibly disclosed to Ollama before public release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcethecybersecguru.com
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.