#pickle

[ follow ]
fromZero Day Initiative
2 days ago

Zero Day Initiative - CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin

For Developers: * Never use pickle for untrusted data: This cannot be emphasized enough. * Never assume checkpoint files are safe: Checkpoint deserialization is vulnerable to supply chain attacks. * Always use weights_only=True when using PyTorch's load functions. * Restrict to trusted classes: Restrict deserialization to only trusted classes. * Implement defense in depth: Don't rely on a single security measure. * Consider alternative formats: Safetensors, ONNX, or other secure serialization formats should all be considered.
Information security
NYC startup
fromBusiness Insider
4 months ago

Meet the women who make thousands a month renting their clothes

Women are making significant income by renting clothes on the app Pickle, using earnings for personal finances and reinvestment.
[ Load more ]